---
id: CVE-2026-56256
title: Capgo - Two-Factor Authentication Bypass via Organization Management API
summary: >-
  Capgo before 12.128.2 enforces mandatory two-factor authentication only at the
  UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing
  organization details, inviting users) do not validate 2FA completion on the
  bac…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'
cvssSource: cna
cwe:
  - CWE-602
vendor: Capgo
product: Capgo
affected:
  - Capgo < 12.128.2
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-24T13:49:21.324827Z'
exploitAvailable: true
published: '2026-06-24'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:25:05.021Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-56256'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-cww4-5xfp-jw98'
    label: GitHub Security Advisory (GHSA-cww4-5xfp-jw98)
  - url: >-
      https://www.vulncheck.com/advisories/capgo-two-factor-authentication-bypass-via-organization-management-api
    label: >-
      VulnCheck Advisory: Capgo - Two-Factor Authentication Bypass via
      Organization Management API
tags:
  - cve.org
  - exploit-available
epss: 0.00414
epssPercentile: 0.33316
ingestedAt: '2026-10-02T01:05:54.739Z'
---

## Overview

Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the backend. An authenticated Admin user who has not enabled 2FA can replay or modify a previously captured ORG API request to perform privileged organization actions, bypassing the globally enforced 2FA requirement.

## Affected

- `Capgo < 12.128.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
