SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-56336

MEDIUM · CVSS 5.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-12 · Last synced 2026-08-11

CyberRota Analysis

AI-Generated

An information disclosure vulnerability exists in Capgo versions prior to 12.128.2, specifically in the unauthenticated /private/sso/check-domain endpoint, which exposes internal org_id and provider_id values. This flaw allows attackers to enumerate email domains, potentially mapping them to organization UUIDs and SSO provider identifiers, facilitating reconnaissance against Capgo tenants. Organizations using Capgo should prioritize patching this vulnerability to mitigate the risk of unauthorized information exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56336
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants.