PT-2026-51765 · Cap Go · Cap-Go
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A cross-domain Single Sign-On (SSO) account takeover issue exists in the 'provision-user' endpoint. The system fails to validate SSO provider domain authorization, allowing the merging of arbitrary victim accounts based on email matches. An attacker with enterprise organization administrator access and a malicious Identity Provider (IdP) can forge Security Assertion Markup Language (SAML) assertions—an XML-based standard for exchanging authentication and authorization data—containing victim email addresses to trigger an account merge and gain full access to victim accounts, organizations, and data.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go