CVE-2026-56303
Capgo
Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.
- CVSS
- 8.7
- EPSS
- 0.30% 22.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11