PT-2026-51502 · Cap Go · Cap-Go

·

CVE-2026-56234

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An issue exists in the 'POST /functions/v1/private/validate password compliance' endpoint that allows credential validation without authentication, requiring only the public Supabase key. The endpoint is CORS-permissive with wildcard origin allowance and lacks rate limiting, which enables attackers to conduct password spraying and credential stuffing attacks to compromise user accounts. Cross-Origin Resource Sharing (CORS) is a mechanism that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56234
GHSA-F6V3-XV4G-79H5

Affected Products

Cap-Go