PT-2026-57555 · Cap Go · Cap-Go
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A cross-organization account disruption issue exists in the SSO prelink endpoint. Enterprise administrators possessing the
org.update settings permission and an active SSO provider can utilize the prelink-users endpoint to permanently delete the password identities of users belonging to other organizations, provided the users match the provider's email domain. This action forces the affected users to either use the attacker's SSO provider or undergo a password reset recovery process.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go