Unrated severityNVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026
Capgo - Scope Isolation Failure in Webhook Test Endpoint
CVE-2026-56252
Description
Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their declared app boundary, bypassing the limited_to_apps authorization check.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-qvr7-f6j6-64wpmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-scope-isolation-failure-in-webhook-test-endpointmitrethird-party-advisory
News mentions
0No linked articles in our index yet.