CVE-2026-53981

HIGH

Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism

Title source: cna
STIX 2.1

Description

Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanently take over the victim's account.

Scores

CVSS v3 7.6
EPSS 0.0027
EPSS Percentile 18.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
Cap-go/Cap-go < 12.128.2
Cap-go/Cap-go 6685e5f11adef257bf3d085e481f4d8ebcec602e
Published Jun 12, 2026
Tracked Since Jun 12, 2026