PT-2026-51771 · Cap Go · Cap-Go

CVE-2026-56256

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description Mandatory two-factor authentication (2FA) is enforced only at the user interface level. Sensitive Organization (ORG) management API endpoints, such as those used for editing organization details or inviting users, fail to validate 2FA completion on the backend. This allows an authenticated Admin user who has not enabled 2FA to bypass the global requirement by replaying or modifying previously captured ORG API requests to perform privileged actions.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56256
GHSA-CWW4-5XFP-JW98

Affected Products

Cap-Go