Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于强制密码策略功能中后端未更新密码合规状态,可能导致超级管理员被永久锁定,无法访问组织。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56073 | 9.4 CRITICAL | Cap-go - OTP Bypass via Response Manipulation in Email Verification |
| CVE-2026-56081 | 9.1 CRITICAL | Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email |
| CVE-2026-56082 | 7.5 HIGH | Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RP |
No comments yet