PT-2026-51780 · Cap Go · Cap-Go
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A denial of service issue exists in the '/auth/v1/otp' endpoint. This flaw prevents authenticated users from completing two-factor authentication (2FA) enrollment because the backend returns HTTP 500 errors during the captcha verification process, effectively blocking access to security controls.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go