CVE-2026-56305: Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56305?
The severity of CVE-2026-56305 is classified as high with a CVSS score of 8.7.
How does CVE-2026-56305 affect Capgo users?
CVE-2026-56305 allows attackers to bypass current password validation, enabling them to change user passwords without authorization.
How do I fix CVE-2026-56305?
To fix CVE-2026-56305, update Capgo to version 12.128.2 or later, which includes the necessary security patch.
Who can exploit CVE-2026-56305?
CVE-2026-56305 can be exploited by attackers with temporary session access to change passwords without current password confirmation.
What are the potential impacts of CVE-2026-56305?
The potential impacts of CVE-2026-56305 include locking out legitimate users and unauthorized access to user accounts.