PatchSiren

CapSoftware CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CapSoftware CVE published 2026-08-11

CVE-2026-69113

CVE-2026-69113 is a broken access control vulnerability in Cap v0.3.1 that allows authenticated users to post comments on private videos without permission. This issue exists in the POST /api/video/comment endpoint, where an arbitrary videoId can be supplied in the request body to bypass access controls. The vulnerability can lead to unauthorized information disclosure or tampering, and defenders responsi [truncated]