Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56320

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validating it matches the target app's owner organization. Authenticated attackers can create device records for an application using a foreign organization identifier, bypassing the intended org/app authorization boundary.

EPSS

Процентиль: 13%
0.00222
Низкий

7.1 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 7.1
github
2 месяца назад

Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validating it matches the target app's owner organization. Authenticated attackers can create device records for an application using a foreign organization identifier, bypassing the intended org/app authorization boundary.

EPSS

Процентиль: 13%
0.00222
Низкий

7.1 High

CVSS3

Дефекты

CWE-285