CVE-2026-56254 HIGH

CVE-2026-56254: capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution

Vendor Capacitor-Updater
Product capacitor-updater
Weakness CWE-320
Published July 10, 2026
Last update July 10, 2026

CVSS base score

8.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.

Key dates

02Disclosure timeline

July 10, 2026 CVE published
July 10, 2026 Record updated