Junglewise Threat Intelligence

CVE-2026-56212: Capgo improper 2FA enforcement logic in team security settings

CVE-2026-56212 · Severity: low · CVSS 3.8 · Published 2026-06-20

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and team workflows, contains a flaw in its security settings management. An administrator can force all other team members to use two-factor authentication (2FA) without having to enable it on their own account first. This creates a security gap where the most powerful accounts remain less protected than standard users and could lead to accidental lockouts or administrative misuse.

Technical details

An authentication logic flaw exists in Capgo's team security settings prior to version 12.128.2. The application fails to perform a prerequisite check on the initiator's 2FA status before allowing them to enable a 'Require 2FA for all team members' policy. An attacker with administrative privileges (PR:H) can exploit this over the network to enforce security policies they do not follow themselves. This results in improper privilege management (CWE-269), potentially leaving administrative accounts vulnerable while disrupting team access or creating inconsistent security postures. The issue is resolved in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-25: advisory: GitHub Advisory GHSA-w2cr-vcwj-69x2 published
  • 2026-06-20: disclosed: CVE-2026-56212 published to NVD
  • 2026-06-20: patched: Fix released in version 12.128.2

References

Related threats