CVE-2026-56323: Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self
Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channelself endpoint that allows unauthenticated attackers to enumerate non-public channel names and determine app existence and subscription status. Remote attackers can send GET requests with arbitrary appid parameters to disclose internal rollout channels, enumerate valid applications across tenants, and leak billing status without authentication or device binding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56323?
CVE-2026-56323 has a high severity rating of 8.7.
How do I fix CVE-2026-56323?
The fix for CVE-2026-56323 involves updating to a patched version of Capgo, specifically version 12.128.2 or later.
What type of vulnerability is CVE-2026-56323?
CVE-2026-56323 is an information disclosure vulnerability that allows unauthenticated attackers to enumerate channel names.
Which endpoint is affected by CVE-2026-56323?
The affected endpoint in CVE-2026-56323 is /functions/v1/channel_self.
Can CVE-2026-56323 be exploited remotely?
Yes, CVE-2026-56323 can be exploited remotely by sending GET requests to the vulnerable endpoint.