PT-2026-51771 · Cap Go · Cap-Go
CVE-2026-56256
·
Published
2026-06-24
·
Updated
2026-06-24
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
Mandatory two-factor authentication (2FA) is enforced only at the user interface level. Sensitive Organization (ORG) management API endpoints, such as those used for editing organization details or inviting users, fail to validate 2FA completion on the backend. This allows an authenticated Admin user who has not enabled 2FA to bypass the global requirement by replaying or modifying previously captured ORG API requests to perform privileged actions.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go