CVE-2026-56286: Capgo - Account Deletion Without Password Confirmation
Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authentication or secondary verification. Attackers can delete user accounts via session hijacking, CSRF attacks, or parameter tampering, resulting in unauthorized account deletion, data loss, and denial-of-service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56286?
CVE-2026-56286 has a severity rating of high with a score of 7.
How do I fix CVE-2026-56286?
To fix CVE-2026-56286, update to Capgo version 12.128.2 or later where the vulnerability has been resolved.
What type of vulnerability is CVE-2026-56286?
CVE-2026-56286 is an authentication bypass vulnerability related to account deletion without password confirmation.
What are the potential attack vectors for CVE-2026-56286?
Potential attack vectors for CVE-2026-56286 include session hijacking, CSRF attacks, and parameter tampering.
What impact does CVE-2026-56286 have on users?
CVE-2026-56286 allows attackers to delete user accounts without authorization, posing a significant risk to user data security.