Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-53981— Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism

CVSS 7.6 · High EPSS 0.27% · P18

Affected Version Matrix 2

VendorProductVersion RangeStatus
Cap-goCap-go< 12.128.2affected
6685e5f11adef257bf3d085e481f4d8ebcec602eunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-53981

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanently take over the victim's account.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键功能的认证机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
Capgo 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Cap-go 12.128.2之前版本存在安全漏洞,该漏洞源于电子邮件更改机制存在账户接管漏洞,可能允许具有临时认证会话访问权限的攻击者无需密码或MFA验证即可更改注册电子邮件地址,并将验证重定向至攻击者控制的电子邮件地址,随后执行密码重置以永久接管受害者账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Cap-goCap-go 0 ~ 12.128.2 -

II. Public POCs for CVE-2026-53981

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 6584 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-53981

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53981 (1)

Vendor Advisories for CVE-2026-53981 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53981

No comments yet


Leave a comment