Junglewise Threat Intelligence

CVE-2026-56081: Cap-go authentication bypass and account lockout via 2FA misconfiguration

CVE-2026-56081 · Severity: critical · CVSS 9.1 · Published 2026-06-19

Technologies: Cap-go. Vendors: Cap-go.

Executive brief

Cap-go, a platform for managing app updates, suffered from a flaw where attackers could register accounts using other people's email addresses without verification. By enabling two-factor authentication on these unverified accounts, an attacker could permanently lock the rightful owner out of the service and gain control over their identity on the platform. This allows unauthorized access to organizational data and prevents legitimate users from ever registering or accessing their own accounts.

Technical details

An authentication logic flaw in Cap-go versions prior to 12.128.2 allowed for 'pre-account takeover' because the platform did not enforce email verification before granting dashboard access. An attacker could register an account using a victim's email address and immediately enable two-factor authentication (2FA) and organization-level 2FA policies. Because the attacker controls the 2FA device, the legitimate owner of the email address is unable to reclaim the account through password resets, resulting in a permanent denial of service and unauthorized control over the identity associated with that email. The vulnerability is addressed in version 12.128.2 by requiring email verification before security controls like 2FA can be configured.

Affected products

  • Cap-go capgo < 12.128.2

Timeline

  • 2026-02-10: advisory: Initial GitHub security advisory published by vendor
  • 2026-06-19: disclosed: CVE published and NVD record created

References