Impact
Capgo before version 12.128.2 allows an attacker who already has a valid session cookie or authenticated browser context to change a user’s email address without re‑authenticating or verifying the current password. Making that change gives the attacker control over the account recovery process, effectively bypassing multi‑factor authentication and leading to full account takeover. The weakness is coded as CWE‑640, indicating insufficient authentication controls.
Affected Systems
The vulnerable product is Capgo. Any instance running a version older than 12.128.2 is affected. Those deployments that have not applied the 12.128.2 release or later are at risk.
Risk and Exploitability
The CVSS score is 8.4, showing high severity, while the EPSS score is below 1 percent, indicating a low exploitation probability in general. The flaw is not listed in CISA KEV yet. A remote attacker only needs to hijack a session or use an authenticated browser, which is a realistic threat vector. The risk remains significant because the impact is complete account compromise and the attacker can use email spoofing, takeover of user control, or bypass authentication mechanisms.
OpenCVE Enrichment