Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在输入验证错误漏洞,该漏洞源于OTP验证中存在身份验证绕过问题,允许攻击者通过修改服务器响应绕过电子邮件验证。攻击者可拦截OTP验证请求并操纵HTTP响应,使其错误标记为验证成功,从而导致未经授权的2FA启用和账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56081 | 9.1 CRITICAL | Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email |
| CVE-2026-56082 | 7.5 HIGH | Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RP |
| CVE-2026-56080 | 4.9 MEDIUM | Cap-go - Authentication Logic Flaw in Enforce Password Policy |
No comments yet