CVE-2026-56228Medium· 4.9▾ SunlitCapgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of cha…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.5%
Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum password length, making compliance impossible for all organization members. Once the policy is enabled, users (including administrators) are unable to change their passwords or access the organization, resulting in an organization-wide account lockout and application-level denial of service.
Capgo < 12.128.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56332Medium· 4.7Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites
CVE-2026-56212Low· 3.8Capgo - Improper 2FA Enforcement Logic via Team Security Settings
CVE-2026-56298Medium· 4.3Capgo - EXIF Metadata Exposure in App Information Image Upload
CVE-2026-56305High· 8.3Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
CVE-2026-56256High· 7.1Capgo - Two-Factor Authentication Bypass via Organization Management API
CVE-2026-53867Medium· 4.3Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement