Description
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.
Published: 2026-07-10
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in Capgo prior to 12.128.2 not validate the user's current password. Attackers who acquire temporary session access can exploit this flaw to change a user’s password, effectively locking out legitimate users and enabling full account takeover. This is a CWE-620 Authentication Bypass by Missing Credential Validation scenario.

Affected Systems

Capgo installations running any version before 12.128.2 are affected. Users who have not applied the update to 12 risk.

Risk and Exploitability

The CVSS score of 8.7, and the EPSS score of < 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only temporary session a user session or use session hijacking techniques. Successful exploitation leads to loss of confidentiality and integrity of user accounts and possible disruption of service.

Generated by OpenCVE AI on July 29, 2026 at 10:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Capgo 12.128.2 or later to fix the authentication bypass.
  • Invalidate all active user sessions to prevent exploitation of any compromised session.
  • Force a password reset for all users to restore account security until the upgrade is complete.

Generated by OpenCVE AI on July 29, 2026 at 10:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go cap-go
Vendors & Products Cap-go
Cap-go cap-go

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.
Title Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T01:44:08.466Z

Reserved: 2026-06-20T12:53:19.893Z

Link: CVE-2026-56305

cve-icon Vulnrichment

Updated: 2026-07-14T01:44:03.602Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:00:13Z

Weaknesses
  • CWE-620

    Unverified Password Change