CVE-2026-56328: Capgo - Integrity Issue in Release Routing via Multiple Public Channels
Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hidden winner channel. An authorized app or channel manager can create ambiguous default update state and silently influence which bundle unnamed clients receive, breaking release routing integrity and predictability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56328?
The severity of CVE-2026-56328 is high with a score of 7.1.
How do I fix CVE-2026-56328?
To fix CVE-2026-56328, update your Capgo software to version 12.128.2 or later.
What kind of vulnerability is CVE-2026-56328?
CVE-2026-56328 is an integrity issue related to release routing via multiple public channels.
What systems are affected by CVE-2026-56328?
CVE-2026-56328 affects Capgo versions prior to 12.128.2.
What risks does CVE-2026-56328 pose?
CVE-2026-56328 can lead to ambiguous default update states, potentially allowing unauthorized channel managers to manipulate app updates.