Security Advisory

CVE-2026-56335

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 13:57:56
Last updated 2026-07-10 14:56:52
Assigner VulnCheck
CVSS score 7.1
State PUBLISHED

Description

Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such as public, allow_emulator, and security-related flags outside intended application routes.