---
id: CVE-2026-56212
title: Capgo - Improper 2FA Enforcement Logic via Team Security Settings
summary: >-
  Capgo before 12.128.2 contains an authentication logic flaw: a user with
  permission to manage team or organization security settings can enable
  mandatory two-factor authentication for all team members without first
  enabling 2FA on their …
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-269
vendor: Capgo
product: Capgo
affected:
  - Capgo < 12.128.2
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-23T02:28:40.182702Z'
exploitAvailable: true
published: '2026-06-20'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:45:19.876Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-56212'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-w2cr-vcwj-69x2'
    label: GitHub Security Advisory (GHSA-w2cr-vcwj-69x2)
  - url: >-
      https://www.vulncheck.com/advisories/capgo-improper-2fa-enforcement-logic-via-team-security-settings
    label: >-
      VulnCheck Advisory: Capgo - Improper 2FA Enforcement Logic via Team
      Security Settings
tags:
  - cve.org
  - exploit-available
epss: 0.00342
epssPercentile: 0.25483
ingestedAt: '2026-10-07T14:33:21.962Z'
---

## Overview

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to verify the initiator's 2FA status before allowing the policy change, resulting in inconsistent security enforcement, potential administrative misuse, and lockout risk for team members.

## Affected

- `Capgo < 12.128.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
