MEDIUM
CapSoftware
CVE published 2026-08-11
CVE-2026-69113
CVE-2026-69113 is a broken access control vulnerability in Cap v0.3.1 that allows authenticated users to post comments on private videos without permission. This issue exists in the POST /api/video/comment endpoint, where an arbitrary videoId can be supplied in the request body to bypass access controls. The vulnerability can lead to unauthorized information disclosure or tampering, and defenders responsi [truncated]