Description
Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections.
Published: 2026-07-12
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Capgo before version 12.128.2 allows an attacker who already has a valid session cookie or authenticated browser context to change a user’s email address without re‑authenticating or verifying the current password. Making that change gives the attacker control over the account recovery process, effectively bypassing multi‑factor authentication and leading to full account takeover. The weakness is coded as CWE‑640, indicating insufficient authentication controls.

Affected Systems

The vulnerable product is Capgo. Any instance running a version older than 12.128.2 is affected. Those deployments that have not applied the 12.128.2 release or later are at risk.

Risk and Exploitability

The CVSS score is 8.4, showing high severity, while the EPSS score is below 1 percent, indicating a low exploitation probability in general. The flaw is not listed in CISA KEV yet. A remote attacker only needs to hijack a session or use an authenticated browser, which is a realistic threat vector. The risk remains significant because the impact is complete account compromise and the attacker can use email spoofing, takeover of user control, or bypass authentication mechanisms.

Generated by OpenCVE AI on August 1, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Capgo to version 12.128.2 or later.
  • Require the current password or a confirmation token when a user attempts to change their email address.
  • Send a verification email to the new address and require user confirmation before the change takes effect.

Generated by OpenCVE AI on August 1, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go cap-go
Vendors & Products Cap-go
Cap-go cap-go

Sun, 12 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections.
Title Capgo - Insufficient Authentication in Email Change Endpoint
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T14:45:07.642Z

Reserved: 2026-06-20T12:53:19.893Z

Link: CVE-2026-56308

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password