PT-2026-51042 · Cap Go · Cap-Go

·

CVE-2026-56212

·

Published

2026-06-20

·

Updated

2026-06-23

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An authentication logic flaw exists where a user authorized to manage team or organization security settings can enforce mandatory two-factor authentication (2FA) for all team members without having 2FA enabled on their own account. The application does not verify the 2FA status of the initiator before permitting the policy change, which can lead to inconsistent security enforcement, administrative misuse, and the risk of locking out team members.
Recommendations Update to version 12.128.2.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56212
GHSA-W2CR-VCWJ-69X2

Affected Products

Cap-Go