CVE-2026-56308: Capgo - Insufficient Authentication in Email Change Endpoint
Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56308?
The severity of CVE-2026-56308 is rated as high with a CVSS score of 7.3.
What vulnerabilities are present in CVE-2026-56308?
CVE-2026-56308 has an insufficient authentication vulnerability that allows email changes without current password verification.
How do I fix CVE-2026-56308?
To fix CVE-2026-56308, update Capgo to version 12.128.2 or later which requires re-authentication for email address changes.
What impact does CVE-2026-56308 have on users?
CVE-2026-56308 can allow attackers to take control of an account by changing the email address if they have access to a valid session.
Who is affected by CVE-2026-56308?
All users of Capgo versions prior to 12.128.2 are affected by CVE-2026-56308 and should take immediate action to secure their accounts.