# CVE-2026-56307

## Summary

- **CVE ID:** CVE-2026-56307
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-670
- **Published:** Jun 20, 2026
- **Last Modified:** Jun 22, 2026

## Description

Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can exploit non-advancing cursor filters to trigger infinite pagination loops, prevent dataset traversal, and cause repeated processing in device-management workflows.

## Affected Products

- Cap-go — capgo (0)
- Cap-go — capgo (12.128.12)

## References

- [CNA](https://github.com/Cap-go/capgo/security/advisories/GHSA-8p6w-x7jg-v4xq)
- [CNA](https://www.vulncheck.com/advisories/cap-go-broken-cursor-pagination-in-private-devices-endpoint)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 30.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._