VYPR
Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026

Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function

CVE-2026-56303

Description

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.