CVE-2026-56336: Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal orgid and providerid values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56336?
CVE-2026-56336 has a medium severity rating of 5.3.
How do I fix CVE-2026-56336?
To mitigate CVE-2026-56336, update to Capgo version 12.128.2 or higher.
What kind of vulnerability is CVE-2026-56336?
CVE-2026-56336 is an information disclosure vulnerability affecting the Capgo application.
What information can be disclosed through CVE-2026-56336?
CVE-2026-56336 allows attackers to obtain internal org_id and provider_id values via the unauthenticated /private/sso/check-domain endpoint.
Who is affected by CVE-2026-56336?
Users of Capgo versions prior to 12.128.2 are affected by CVE-2026-56336.