Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
CVE-2026-56313: Capgo SSO Prelink Vulnerability - Account Deletion via SSO
CVE-2026-56313
CVE-2026-56313
Summary
A vulnerability in Capgo's SSO prelink endpoint allows an attacker to delete a user's email-based authentication, forcing them to use the attacker's SSO provider or reset their password. This can happen if an attacker has permission to update settings and can access the SSO provider. To protect against this, ensure you have the latest version of Capgo installed, and consider limiting access to SSO settings.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| capgo | capgo | < 12.128.2 |
Original title
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in fore...
Original description
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider's email domain, forcing victims to use the attacker's SSO provider or complete password reset recovery.
nvd CVSS3.1
8.1
nvd CVSS4.0
7.2
Vulnerability type
CWE-285
Improper Authorization
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026