CVE-2026-56254
CVE-2026-56254 is a high-severity vulnerability with a CVSS 3.x base score of 7.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-320.
Key facts
- Severity: High (CVSS 3.x base score 7.0)
- CVSS v4: 8.3
- EPSS exploit prediction: 0% (5th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-320
- Published:
- Last modified:
Description
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.
Frequently asked questions
- What is CVE-2026-56254?
- In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.
- How severe is CVE-2026-56254?
- CVE-2026-56254 has a CVSS 3.x base score of 7.0, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity high, and availability low.
- Is CVE-2026-56254 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (5th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-56254?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-56254 published?
- CVE-2026-56254 was published on 2026-07-10.
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-j2f4-4pfc-p8rx
- https://www.vulncheck.com/advisories/capacitor-updater-end-to-end-encryption-bypass-via-private-key-distribution
Other CWE-320 vulnerabilities
- CVE-2016-10467 — Critical (CVSS 9.8): In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD…
- CVE-2016-10421 — Critical (CVSS 9.8): In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206,…
- CVE-2018-0124 — Critical (CVSS 9.8): A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to…
- CVE-2015-0936 — Critical (CVSS 9.8): Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows…
- CVE-2015-4166 — Critical (CVSS 9.8): Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have…
- CVE-2024-36391 — Critical (CVSS 9.1): MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic