Impact
Capgo versions prior to 12.128.2 contain a flaw in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in other organizations. By removing the email‑based authentication token for users whose email address belongs to the attacker’s SSO provider, the victim organization loses the ability to log in with a password and is forced to either rely on the attacker’s SSO provider or trigger a password‑reset flow. This attack effectively disables standard authentication for any affected user within the target organization.
Affected Systems
The affected product is Capgo, specifically instances running a version earlier than 12.128.2. The vulnerability is tied to the SSO prelink feature that links external SSO providers to local user accounts. No additional vendor product variants or version ranges are listed beyond this threshold, so any Capgo installation prior to 12.128.2 that enables the SSO prelink endpoint is potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack requires that the adversary have org.update_settings permissions and that an SSO provider is active, meaning an attacker must already have an account with those rights. The cross‑organization nature of the flaw means that a single compromised administrator could affect another organization. Given the EPSS score is low, the likelihood of exploitation in the wild appears limited, but the potential disruption makes the vulnerability a high‑risk target for organizations that use Capgo. The CWE identifier for this weakness is 285, which denotes broken access control in the access‑control subsystem.
OpenCVE Enrichment