Impact
The vulnerability is a missing authentication flaw (CWE-862) that allows any party to call the get_orgs_v7 RPC endpoint with an arbitrary user UUID. Because no identity verification is performed, unauthenticated attackers receive detailed membership, role, management email, and billing information for any user in the system. This enables the exposure of confidential organizational structure and financial data.
Affected Systems
Capgo releases prior to version 12.128.2 are affected. The vendor is Capgo by Capgo.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score below 1% signals a low overall exploitation probability. Nevertheless, the endpoint is publicly reachable without authentication, making exploitation trivial for anyone who can reach the RPC service. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by sending a request to the get_orgs_v7 RPC with any user UUID parameter. No additional privileges or credentials are required.
OpenCVE Enrichment