Junglewise Threat Intelligence

CVE-2026-56228: Capgo improper input validation in password policy configuration

CVE-2026-56228 · Severity: medium · CVSS 4.9 · Published 2026-06-20

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and configurations, contains a flaw in its password policy settings. An administrator can accidentally or maliciously set a minimum password length to an impossible number, such as billions of characters. This results in an organization-wide lockout where no users, including administrators, can log in or update their credentials, effectively shutting down access to the platform.

Technical details

A business logic vulnerability exists in Capgo's password policy configuration due to improper input validation (CWE-20). The application fails to enforce a reasonable upper bound on the 'minimum password length' field. An authenticated attacker with administrative privileges can submit an extremely large integer (e.g., billions) for this setting. Once applied, the system requires all users to meet this impossible criteria during authentication or password resets. This results in a permanent application-level denial of service (DoS) and account lockout for the entire organization. The issue is resolved in version 12.128.2 by implementing server-side validation and strict maximum limits.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-19: advisory: Initial GitHub security advisory published
  • 2026-06-20: disclosed: CVE published to NVD dataset

References

Related threats