Security Advisory

CVE-2026-56318

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-30 22:08:29
Last updated 2026-07-01 13:17:49
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid organization UUIDs by observing response status codes and error messages, allowing confirmation of organization existence.