Description
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider's email domain, forcing victims to use the attacker's SSO provider or complete password reset recovery.
Published: 2026-07-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Capgo versions prior to 12.128.2 contain a flaw in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in other organizations. By removing the email‑based authentication token for users whose email address belongs to the attacker’s SSO provider, the victim organization loses the ability to log in with a password and is forced to either rely on the attacker’s SSO provider or trigger a password‑reset flow. This attack effectively disables standard authentication for any affected user within the target organization.

Affected Systems

The affected product is Capgo, specifically instances running a version earlier than 12.128.2. The vulnerability is tied to the SSO prelink feature that links external SSO providers to local user accounts. No additional vendor product variants or version ranges are listed beyond this threshold, so any Capgo installation prior to 12.128.2 that enables the SSO prelink endpoint is potentially vulnerable.

Risk and Exploitability

The CVSS score is 7.2, indicating a high severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack requires that the adversary have org.update_settings permissions and that an SSO provider is active, meaning an attacker must already have an account with those rights. The cross‑organization nature of the flaw means that a single compromised administrator could affect another organization. Given the EPSS score is low, the likelihood of exploitation in the wild appears limited, but the potential disruption makes the vulnerability a high‑risk target for organizations that use Capgo. The CWE identifier for this weakness is 285, which denotes broken access control in the access‑control subsystem.

Generated by OpenCVE AI on August 1, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Capgo 12.128.2 patch or newer to remove the vulnerability.
  • Disable the SSO prelink endpoint until the patch is applied.
  • Monitor SSO‑related logs for abnormal account deletion activities.

Generated by OpenCVE AI on August 1, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go cap-go
Vendors & Products Cap-go
Cap-go cap-go

Sun, 12 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider's email domain, forcing victims to use the attacker's SSO provider or complete password reset recovery.
Title Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-13T16:01:22.299Z

Reserved: 2026-06-20T12:59:07.917Z

Link: CVE-2026-56313

cve-icon Vulnrichment

Updated: 2026-07-13T16:01:18.183Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses