CVE-2026-56240
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with ex
CVSS
4.3
Medium
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Jul 11, 2026 · Last modified: Jul 13, 2026 · CWE-285
0.2%EPSS · 30 days0.3%
2026-08-132026-09-09
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-804368.5 HIG—
———IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.5hCVE-2026-803788.5 HIG—
———IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.5hCVE-2026-855434.3 MED—
———Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.12hCVE-2026-210976.7 MED2.8%
——1Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.7hCVE-2026-868045.3 MED31.4%
——9A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.2dCVE-2026-586117.8 HIG12.3%
——4Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.2d