PT-2026-51039 · Cap Go · Cap-Go

CVE-2026-56081

·

Published

2026-06-19

·

Updated

2026-06-20

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cap-go versions prior to 12.128.2
Description An authentication logic flaw allows an attacker to register and control an account linked to a victim's email address before the email is verified. By enabling two-factor authentication on this pre-registered account, the attacker can seize control of the account claimed under the victim's identity. This enables the attacker to read and modify the account state and enforce organization-level policies, while the legitimate user is prevented from accessing the account associated with their own email.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56081
GHSA-J4CX-5PW6-5V5J

Affected Products

Cap-Go