CVE-2026-56305

HIGH

Capgo - Authentication Bypass in Password Change via Missing Current Password Validation

Title source: cna
STIX 2.1

Description

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-rjr5-qxqj-cx8g)
https://github.com/Cap-go/capgo/security/advisories/GHSA-rjr5-qxqj-cx8g
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
https://www.vulncheck.com/advisories/capgo-authentication-bypass-in-password-change-via-missing-current-password-validation

Scores

CVSS v3 8.3
EPSS 0.0036
EPSS Percentile 28.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-620
Status published
Products (2)
Capgo/Capgo < 12.128.2
Capgo/Capgo 12.128.2
Published Jul 10, 2026
Tracked Since Jul 10, 2026