CVE-2026-56224: Capgo - Login CSRF and Session Fixation via URL Query Parameters

Published Jun 30, 2026
·
Updated

Capgo console.capgo.app/login before 12.128.2 accepts accesstoken and refreshtoken in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.

Affected Software

1 affected component
capgo<12.128.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade capgo console.capgo.app/login to a version that resolves this vulnerability.

    Fixed in 12.128.2
  2. Configuration

    Update Capgo so that before 12.128.2 the /login endpoint no longer accepts access_token and refresh_token in URL query parameters that auto-authenticate users.

    Capgo console.capgo.app/login accept access_token and refresh_token in URL query parameters = disable (require tokens via non-URL mechanism or explicit confirmation)
  3. Compensating control

    Block or sanitize inbound links that include URL query parameters containing access_token or refresh_token to prevent login CSRF/session fixation attempts.

Event History

Jun 30, 2026
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-56224?

CVE-2026-56224 has a severity rating of medium with a score of 5.1.

2

How do I fix CVE-2026-56224?

To fix CVE-2026-56224, update to the latest version of Capgo that addresses the CSRF and session fixation vulnerabilities.

3

What are the potential impacts of CVE-2026-56224?

Exploitation of CVE-2026-56224 can lead to unauthorized account access due to session hijacking via user tokens.

4

How does CVE-2026-56224 exploit user sessions?

CVE-2026-56224 allows attackers to craft URLs that authenticate users automatically, potentially leading to unauthorized access.

5

Is user confirmation required in CVE-2026-56224?

No, CVE-2026-56224 allows automatic authentication without user confirmation, making it especially risky.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203