Beveiligingsadvies

CVE-2026-56318

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-30 22:08:29
Laatst bijgewerkt 2026-07-01 13:17:49
Toegewezen door VulnCheck
CVSS-score 6.9
Status PUBLISHED

Beschrijving

Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid organization UUIDs by observing response status codes and error messages, allowing confirmation of organization existence.