CVE-2026-56318: Capgo - Information Disclosure via /private/validate_password_compliance Endpoint
Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validatepasswordcompliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid organization UUIDs by observing response status codes and error messages, allowing confirmation of organization existence.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56318?
The severity of CVE-2026-56318 is classified as medium, with a score of 6.9.
How can I mitigate CVE-2026-56318?
To mitigate CVE-2026-56318, upgrade to Capgo version 12.128.2 or later, where the vulnerability is addressed.
What type of vulnerability is CVE-2026-56318?
CVE-2026-56318 is classified as an information disclosure vulnerability.
Who can exploit CVE-2026-56318?
Unauthenticated attackers can exploit CVE-2026-56318 to enumerate valid organization UUIDs.
What endpoint is affected by CVE-2026-56318?
CVE-2026-56318 affects the /private/validate_password_compliance endpoint in Capgo.