Back to overview

CVE-2026-56256

HIGH Exploitation: PoC
7.1
CVSS 3.1
Description
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the backend. An authenticated Admin user who has not enabled 2FA can replay or modify a previously captured ORG API request to perform privileged organization actions, bypassing the globally enforced 2FA requirement.

Metadata

CVE ID
CVE-2026-56256
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-19 21:56 UTC
Published
2026-06-24 11:53 UTC
Last updated
2026-06-24 13:49 UTC
Primary CWE
CWE-602
Client-Side Enforcement of Server-Side Security
Vendor / Product
Capgo / Capgo
Sources
cve.org  ·  NVD

Severity & Metrics

7.1 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Capgo Capgo 0 < 12.128.2, 12.128.2
Weakness (CWE)
CWESourceDescription
CWE-602 cna Client-Side Enforcement of Server-Side Security
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.1 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
7.1 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
References (2)
Back to overview