---
id: CVE-2026-56294
title: >-
  capacitor-native-biometric before 12.128.2 contains an authentication bypass
  vulnerability where the onAuthenticationSucceeded() method fails to validate
  CryptoObject parameters
summary: >-
  capacitor-native-biometric before 12.128.2 contains an authentication bypass
  vulnerability where the onAuthenticationSucceeded() method fails to validate
  CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded()
  functio…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-287
vendor: capacitor-native-biometric
product: capacitor-native-biometric
affected:
  - capacitor-native-biometric < 12.128.2
published: '2026-06-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:21.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56294'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-vx5f-vmr6-32wf'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/capacitor-native-biometric-authentication-bypass-via-unvalidated-cryptoobject-in-onauthenticationsucceeded
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-vx5f-vmr6-32wf'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-22T12:44:05.836072Z'
epss: 0.00217
epssPercentile: 0.11122
ingestedAt: '2026-10-08T16:52:14.690Z'
---

## Overview

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass biometric authentication without valid credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
