Impact
Capgo versions older than 12.128.2 expose internal organization UUIDs and SSO provider identifiers through a public API endpoint that requires no authentication. Attacks can gather the organization ID and the provider ID for any queried email domain, allowing an adversary to map external domains to tenant identifiers and the identity providers they use. This vulnerability enables detailed reconnaissance of Capgo tenant infrastructure, which may enable attackers to plan further attacks, inferred from the disclosed data.
Affected Systems
Capgo deployments running any version before 12.128.2 are affected. Based on the description, the unauthenticated /private/sso/check-domain endpoint can be accessed by any host that can reach the Capgo server over the network, regardless of user credentials.
Risk and Exploitability
The CVSS score of 6.9 classifies this vulnerability as medium severity. The EPSS score of less than 1% indicates that exploitation attempts are presently rare, and the issue is not listed in the CISA KeV catalog. However, based on the description, it is inferred that the endpoint is publicly reachable to any host with network connectivity to the Capgo instance, implying a remote network attack vector. Because the API delivers sensitive internal data without access controls, the attack surface remains broad and the potential impact on confidentiality must be mitigated promptly.
OpenCVE Enrichment