CVE-2026-56320: Capgo - Org/App Scope Mismatch in Device Creation Endpoint
Capgo before 12.128.2 contains an authorization flaw in POST /private/createdevice that accepts a caller-supplied orgid parameter without validating it matches the target app's owner organization. Authenticated attackers can create device records for an application using a foreign organization identifier, bypassing the intended org/app authorization boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56320?
The severity of CVE-2026-56320 is rated as high with a score of 7.1.
What does CVE-2026-56320 impact?
CVE-2026-56320 impacts the Capgo software, specifically the POST /private/create_device endpoint.
How do I fix CVE-2026-56320?
To fix CVE-2026-56320, update Capgo to version 12.128.2 or later which addresses the authorization flaw.
What type of vulnerability is CVE-2026-56320?
CVE-2026-56320 is an authorization flaw allowing attackers to create device records using a foreign organization ID.
Who is affected by CVE-2026-56320?
Users and organizations utilizing versions of Capgo prior to 12.128.2 are affected by CVE-2026-56320.