THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-56336 (MEDIUM 5.3) — Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO p

[NVD] CVE-2026-56336 (MEDIUM 5.3) — Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO p

lownvdPublished 2026-07-12

CVE-2026-56336 CVSS: 5.3 MEDIUM Published: 2026-07-12T12:16:45.837

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56336