Capgo versions before 12.128.2 have an information disclosure vulnerability in an unauthenticated endpoint (/private/sso/check-domain) that reveals… (CVE-2026-56336)
Capgo versions before 12.128.2 have an information disclosure vulnerability in an unauthenticated endpoint (/private/sso/check-domain) that reveals internal organization and provider identifiers. This allows attackers to enumerate email domains and map them to organization UUIDs and SSO provider IDs, facilitating reconnaissance against Capgo tenants.
AI Analysis
Technical Summary
The vulnerability in Capgo prior to version 12.128.2 involves an unauthenticated information disclosure via the /private/sso/check-domain endpoint. This endpoint returns sensitive internal identifiers such as org_id and provider_id. Attackers can exploit this to enumerate email domains and correlate them with internal organization UUIDs and single sign-on (SSO) provider identifiers. This reconnaissance capability could aid in further targeted attacks against Capgo tenants. The vulnerability is classified under CWE-200 (Information Exposure).
Potential Impact
The vulnerability allows unauthenticated attackers to obtain internal organization and SSO provider identifiers by querying an exposed endpoint. This information disclosure can be used to map email domains to internal identifiers, enabling attackers to perform reconnaissance on Capgo tenants. There is no indication of direct system compromise or data modification from this vulnerability alone.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. Until a fix is available, restricting access to the /private/sso/check-domain endpoint or implementing authentication controls may reduce exposure.
Capgo versions before 12.128.2 have an information disclosure vulnerability in an unauthenticated endpoint (/private/sso/check-domain) that reveals… (CVE-2026-56336)
Description
Capgo versions before 12.128.2 have an information disclosure vulnerability in an unauthenticated endpoint (/private/sso/check-domain) that reveals internal organization and provider identifiers. This allows attackers to enumerate email domains and map them to organization UUIDs and SSO provider IDs, facilitating reconnaissance against Capgo tenants.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Capgo prior to version 12.128.2 involves an unauthenticated information disclosure via the /private/sso/check-domain endpoint. This endpoint returns sensitive internal identifiers such as org_id and provider_id. Attackers can exploit this to enumerate email domains and correlate them with internal organization UUIDs and single sign-on (SSO) provider identifiers. This reconnaissance capability could aid in further targeted attacks against Capgo tenants. The vulnerability is classified under CWE-200 (Information Exposure).
Potential Impact
The vulnerability allows unauthenticated attackers to obtain internal organization and SSO provider identifiers by querying an exposed endpoint. This information disclosure can be used to map email domains to internal identifiers, enabling attackers to perform reconnaissance on Capgo tenants. There is no indication of direct system compromise or data modification from this vulnerability alone.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. Until a fix is available, restricting access to the /private/sso/check-domain endpoint or implementing authentication controls may reduce exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g3p6-j9ww-hmwc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56336"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a54ae1668715ace438f973a
Added to database: 07/13/2026, 09:21:26 UTC
Last enriched: 07/13/2026, 10:00:55 UTC
Last updated: 07/31/2026, 20:14:02 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.