CVE-2026-56333: Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Security Settings Updates
Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allows authenticated org admins to persist invalid security policy state. Attackers can bypass backend validation by directly updating the public.orgs table from the browser, circumventing field-level validation checks for maxapikeyexpirationdays and other security-sensitive configuration parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56333?
CVE-2026-56333 has a medium severity score of 5.3.
How do I fix CVE-2026-56333?
To fix CVE-2026-56333, update Capgo to version 12.128.2 or later where the vulnerability is addressed.
What does CVE-2026-56333 exploit?
CVE-2026-56333 exploits a server-side validation bypass vulnerability in organization security settings.
Who is affected by CVE-2026-56333?
Authenticated organization administrators in Capgo prior to version 12.128.2 are affected by CVE-2026-56333.
What are the potential impacts of CVE-2026-56333?
The potential impacts of CVE-2026-56333 include the ability for attackers to persist invalid security policy states.