capgo has 12 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 8. The median CVSS is 5.1 (medium). None have a confirmed exploitation report. Most affected products: Capgo (11), cli (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 10
Worst active — by depth score
CVE-2026-56223High· 8.7Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…60CVE-2026-56305High· 8.3Capgo - Authentication Bypass in Password Change via Missing Current Password Validation58CVE-2026-56256High· 7.1Capgo - Two-Factor Authentication Bypass via Organization Management API51CVE-2026-56236Medium· 6.1Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation46CVE-2026-56336Medium· 5.3Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values41
capgo vulnerabilities
CVEs affecting capgo, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-56336Medium· 5.3PoCCapgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings…
CVE-2026-56281Low· 3.8PoCCapgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL…
Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL…
CVE-2026-56305High· 8.3PoCCapgo - Authentication Bypass in Password Change via Missing Current Password Validation
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access…
CVE-2026-56298Medium· 4.3Capgo - EXIF Metadata Exposure in App Information Image Upload
Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location informatio…
CVE-2026-56256High· 7.1PoCCapgo - Two-Factor Authentication Bypass via Organization Management API
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the bac…
CVE-2026-56223High· 8.7PoCCapgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…
Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…
CVE-2026-56236Medium· 6.1PoCCapgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation
Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary…
CVE-2026-56332Medium· 4.7PoCCapgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites
Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites. The confirmation_url parameter is not validated, enabling attackers to c…
CVE-2026-56228Medium· 4.9Capgo - Denial of Service via Improper Password Policy Length Validation
Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of cha…
CVE-2026-56212Low· 3.8PoCCapgo - Improper 2FA Enforcement Logic via Team Security Settings
Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their …
CVE-2026-53867Medium· 4.3Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval…
CVE-2026-53868High· 7.5Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion
Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can…