Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
Capgo - Information Disclosure via /private/validate_password_compliance Endpoint
CVE-2026-56318
Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid organization UUIDs by observing response status codes and error messages, allowing confirmation of organization existence.
Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-fwwh-rqv7-6pjfmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-information-disclosure-via-private-validate-password-compliance-endpointmitrethird-party-advisory
News mentions
0No linked articles in our index yet.