CVE-2026-56327: Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC
Capgo before 12.128.2 contains an information disclosure vulnerability in the public.inviteusertoorg RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NOORG versus NORIGHTS responses, enabling tenant enumeration attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgo (public.invite_user_to_org RPC)to a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56327?
CVE-2026-56327 has a severity rating of medium, specifically rated at 6.9.
How do I fix CVE-2026-56327?
To address CVE-2026-56327, upgrade Capgo to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56327?
CVE-2026-56327 is an information disclosure vulnerability related to organization enumeration.
Who is affected by CVE-2026-56327?
Any user of Capgo versions before 12.128.2 is affected by CVE-2026-56327.
What is the impact of CVE-2026-56327?
CVE-2026-56327 allows unauthenticated attackers to enumerate organizations by leveraging specific error responses.