Capgo versions before 12.128.2 have a scope isolation vulnerability in the POST /webhooks/test endpoint. (CVE-2026-56252)
Capgo versions before 12.128.2 have a scope isolation vulnerability in the POST /webhooks/test endpoint. This flaw allows app-scoped API keys to invoke organization-scoped webhook operations, bypassing the intended authorization checks that limit API keys to their declared app boundaries. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their app scope.
AI Analysis
Technical Summary
The vulnerability in Capgo prior to version 12.128.2 involves improper scope isolation in the POST /webhooks/test endpoint. Specifically, app-scoped API keys can be used to perform operations intended only for organization-scoped keys, effectively bypassing the limited_to_apps authorization check. This allows an attacker with app-scoped credentials to trigger signed outbound webhook deliveries for organization webhooks outside their authorized app boundary. The issue is classified under CWE-863 (Incorrect Authorization). No patch or official fix information is provided in the available data.
Potential Impact
An attacker possessing app-scoped API keys can bypass authorization restrictions and invoke organization-scoped webhook operations. This could lead to unauthorized triggering of signed outbound webhooks for organizations beyond the attacker's app scope, potentially enabling unauthorized actions or information disclosure related to those webhooks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict the use of app-scoped API keys and monitor webhook usage for unusual activity related to cross-scope invocations.
Capgo versions before 12.128.2 have a scope isolation vulnerability in the POST /webhooks/test endpoint. (CVE-2026-56252)
Description
Capgo versions before 12.128.2 have a scope isolation vulnerability in the POST /webhooks/test endpoint. This flaw allows app-scoped API keys to invoke organization-scoped webhook operations, bypassing the intended authorization checks that limit API keys to their declared app boundaries. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their app scope.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Capgo prior to version 12.128.2 involves improper scope isolation in the POST /webhooks/test endpoint. Specifically, app-scoped API keys can be used to perform operations intended only for organization-scoped keys, effectively bypassing the limited_to_apps authorization check. This allows an attacker with app-scoped credentials to trigger signed outbound webhook deliveries for organization webhooks outside their authorized app boundary. The issue is classified under CWE-863 (Incorrect Authorization). No patch or official fix information is provided in the available data.
Potential Impact
An attacker possessing app-scoped API keys can bypass authorization restrictions and invoke organization-scoped webhook operations. This could lead to unauthorized triggering of signed outbound webhooks for organizations beyond the attacker's app scope, potentially enabling unauthorized actions or information disclosure related to those webhooks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict the use of app-scoped API keys and monitor webhook usage for unusual activity related to cross-scope invocations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4w58-4949-9w2m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56252"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a54ae1968715ace438f9cf4
Added to database: 07/13/2026, 09:21:29 UTC
Last enriched: 07/13/2026, 10:01:43 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.