Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.4
CVE-2026-56308: Capgo - Email Change Allows Unauthorized Account Access
CVE-2026-56308
CVE-2026-56308
Summary
Capgo before version 12.128.2 has a security weakness that allows an attacker to change an account's email address without needing to know the current password. This could allow an attacker to gain control of account recovery and bypass multi-factor authentication. To fix this, update Capgo to version 12.128.2 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| capgo | capgo | < 12.128.2 |
Original title
Capgo - Insufficient Authentication in Email Change Endpoint
Original description
Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections.
nvd CVSS3.1
7.3
nvd CVSS4.0
8.4
Vulnerability type
CWE-640
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026