Beveiligingsadvies

CVE-2026-56335

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-10 13:57:56
Laatst bijgewerkt 2026-07-10 14:56:52
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such as public, allow_emulator, and security-related flags outside intended application routes.