Junglewise Threat Intelligence

CVE-2026-56308: Capgo insufficient authentication in email change endpoint

CVE-2026-56308 · Severity: high · CVSS 7.3 · Published 2026-07-12

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates, contained a security flaw that allowed users to change their account email address without providing their current password. If an attacker gains temporary access to a user's logged-in session or browser, they could change the email address to one they control. This allows the attacker to hijack the account recovery process, effectively locking out the legitimate owner and bypassing security protections like multi-factor authentication.

Technical details

The vulnerability is classified as an insufficient authentication flaw (CWE-640) within the account settings endpoint of the Capgo console. The application trusted an active session cookie or bearer token as sufficient proof of identity for sensitive account modifications, failing to require a password re-entry or 'sudo mode' check. An attacker who obtains a valid session (via XSS, session fixation, or physical access to an unlocked device) can update the primary email address. This enables full account takeover by redirecting password reset flows and recovery notifications to an attacker-controlled address. The issue is resolved in version 12.128.2, which implements stricter verification for email changes.

Affected products

  • Capgo Capgo before 12.128.2

Timeline

  • 2026-02-25: advisory: Initial GitHub Security Advisory published
  • 2026-07-12: disclosed: CVE published to NVD dataset

References

Related threats