CVE-2026-56322: Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allowing attackers to enumerate private channels and leak version/config state. Unauthenticated attackers can probe private channel names and distinguish valid channels from nonexistent ones based on response differences, revealing assigned bundle versions and platform-specific configuration details.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56322?
CVE-2026-56322 has a severity rating of high with a score of 7.5.
How do I fix CVE-2026-56322?
To fix CVE-2026-56322, update Capgo to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56322?
CVE-2026-56322 is an information disclosure vulnerability.
What can attackers do with CVE-2026-56322?
Attackers can exploit CVE-2026-56322 to enumerate private channels and leak version and configuration state.
In which software is CVE-2026-56322 found?
CVE-2026-56322 is found in Capgo prior to version 12.128.2.