Junglewise Threat Intelligence

CVE-2026-56305: Capgo authentication bypass in password change endpoint

CVE-2026-56305 · Severity: high · CVSS 8.3 · Published 2026-07-10

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and configurations, contained a security flaw in its password management system. An attacker who gains temporary access to a user's active session could change the account password without knowing the original one. This allows an unauthorized person to permanently lock the legitimate owner out of their account and take full control of their data and operations.

Technical details

An authentication bypass vulnerability exists in Capgo's password change endpoint due to a lack of current password validation (CWE-620). The backend fails to enforce a requirement for the existing password before accepting a new one, relying solely on the presence of an active session token. A remote attacker who has obtained a valid session—via session hijacking, XSS, or shared device access—can submit a password change request to the console settings. This results in a full account takeover and permanent lockout of the original user. The issue is resolved in version 12.128.2, which implements mandatory server-side validation of the current password.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-10: advisory: Initial GHSA advisory published
  • 2026-07-10: disclosed: CVE published to NVD

References

Related threats