CVE-2026-56081

CRITICAL

Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email

Title source: cna
STIX 2.1

Description

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's identity, allowing them to read and modify its state and enforce organization-level policies, while the legitimate user is denied access to the account tied to their own email.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-j4cx-5pw6-5v5j
https://github.com/Cap-go/capgo/security/advisories/GHSA-j4cx-5pw6-5v5j
Third Party Advisory third-party-advisory
VulnCheck Advisory: Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email
https://www.vulncheck.com/advisories/cap-go-account-lockout-via-2fa-misconfiguration-on-unverified-email

Scores

CVSS v3 9.1
EPSS 0.0057
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-640
Status published
Products (2)
Cap-go/capgo < 12.128.2
Cap-go/capgo 12.128.2
Published Jun 19, 2026
Tracked Since Jun 20, 2026