CVE-2026-56335: Capgo - Channel Configuration Mutation via Write-Scoped API Keys
Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such as public, allowemulator, and security-related flags outside intended application routes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56335?
The severity of CVE-2026-56335 is rated high with a score of 7.1.
How do I fix CVE-2026-56335?
To fix CVE-2026-56335, update to Capgo version 12.128.2 or later.
What are the risks associated with CVE-2026-56335?
CVE-2026-56335 poses a risk allowing attackers with write API keys to mutate protected channel configurations.
Who is affected by CVE-2026-56335?
CVE-2026-56335 affects users of Capgo prior to version 12.128.2.
What type of vulnerability is CVE-2026-56335?
CVE-2026-56335 is an authorization bypass vulnerability due to a null authentication check.