CVE-2026-56323

Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and determine app existence and subscription status. Remote attackers can send GET requests with arbitrary app_id parameters to disclose internal rollout channels, enumerate valid applications across tenants, and leak billing status without authentication or device binding.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-22 22:16

Updated : 2026-06-23 16:17


NVD link : CVE-2026-56323

Mitre link : CVE-2026-56323

CVE.ORG link : CVE-2026-56323


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor