Description
Capgo Console prior to 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to be redirected to an account-disabled page for approximately 30 days, preventing any account login or registration from that device.
Published: 2026-06-12
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Capgo Console versions prior to 12.28.2 contain a flaw in the account deletion flow that mis‑associates the deletion state with a device identifier. When an authenticated user triggers account deletion while a device identifier is linked to the active session, the platform marks that device as deleted and redirects it to an account‑disabled page for roughly 30 days. During that period the affected device or browser cannot log in or register a new account, effectively denying the user service. This vulnerability is categorized as a wrong‑identification of authorization state, corresponding to CWE-645.

Affected Systems

All users running Cap‑Go Console before version 12.28.2. The vulnerability affects the console component hosted at console.capgo.app and is not tied to a specific minor release but applies to any build older than 12.28.2. Manufacturing or deployment of the console at specific versions is not further detailed in the advisory.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact if exploited. The exploit probability (EPSS) is currently not disclosed, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need ability to trigger the account‑deletion workflow, which typically implies that the attacker has obtained credentials or otherwise can initiate the deletion from a device already linked to the session. The risk therefore is moderate to high for compromised or privileged accounts, as denial of service will be experienced by the affected device for about a month until a new device identifier is assigned or the deletion flag is cleared. The attack vector is inferred to be remote user‑initiated deletion through the web interface or API; no exploitation of external network services is required beyond standard authentication.

Generated by OpenCVE AI on June 12, 2026 at 20:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Capgo Console to version 12.28.2 or newer to apply the vendor fix
  • If an upgrade cannot be performed immediately, isolate the affected device or remove its device identifier from the session before performing account deletion to avoid the deletion state being propagated
  • Continuously monitor authentication and deletion logs for repeated or anomalous deletion requests that may indicate exploitation attempts

Generated by OpenCVE AI on June 12, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go console.capgo.app
Vendors & Products Cap-go
Cap-go console.capgo.app

Fri, 12 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 12 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-645

Fri, 12 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Capgo Console prior to 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to be redirected to an account-disabled page for approximately 30 days, preventing any account login or registration from that device.
Title Capgo Console < 12.28.2 Account Deletion DoS via Device Identifier Association
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cap-go Console.capgo.app
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-12T20:52:00.994Z

Reserved: 2026-06-11T16:07:13.000Z

Link: CVE-2026-53982

cve-icon Vulnrichment

Updated: 2026-06-12T20:51:55.530Z

cve-icon NVD

Status : Received

Published: 2026-06-12T17:16:26.727

Modified: 2026-06-12T19:16:30.647

Link: CVE-2026-53982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T20:30:06Z

Weaknesses
  • CWE-645

    Overly Restrictive Account Lockout Mechanism