CVE-2026-56308

HIGH CVSS 4.0: 8.4 EPSS 0.43%
Updated Jul 14, 2026
Capgo
Parameter Value
CVSS 8.4 (HIGH)
Affected Versions before 12.128.2
Type CWE-640
Vendor Capgo
Public PoC No

Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)