Cap Go · Cap-Go · CVE-2026-56073
**Name of the Vulnerable Software and Affected Versions**
Cap-go versions prior to 12.128.2
**Description**
An authentication bypass exists in the OTP (One-Time Password) verification process. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely indicate that verification was successful. This allows for the unauthorized enablement of two-factor authentication (2FA) and subsequent account takeover.
**Recommendations**
Update to version 12.128.2 or later.