# CVE-2026-56327

> Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NO_ORG versus NO_RIGHTS responses, enabling tenant enumeration attacks.

- **CVSS:** 5.3 (MEDIUM)
- **EPSS:** 0.3%
- **CWE:** CWE-203

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-56327
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
