CVE-2026-59704
Cap
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent.
- CVSS
- 7.1
- EPSS
- 0.22% 12.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08