Executive brief
Capgo, a platform for managing web application updates, contained a flaw in its account management system. This vulnerability allowed user accounts to be permanently deleted without requiring a password or any form of secondary verification. An attacker could exploit this to cause irreversible data loss, disrupt business operations, and prevent legitimate users from accessing their accounts.
Technical details
A missing authentication check for a critical function (CWE-306) exists in the Capgo account deletion endpoint. The server-side logic failed to require a password, MFA token, or session re-authentication before processing a destructive deletion request. This flaw makes the endpoint susceptible to Cross-Site Request Forgery (CSRF), session hijacking, or parameter tampering. An attacker who can influence a victim's browser or obtain a session token can trigger an immediate 'hard delete' of the user's profile, billing history, and associated data. The vulnerability is addressed in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-02-10: advisory: Initial GitHub Security Advisory published by the vendor
- 2026-06-30: disclosed: CVE-2026-56286 published to the NVD
- 2026-06-30: patched: Fix released in version 12.128.2