Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于修改电子邮件地址时未要求重新验证当前密码或验证现有电子邮件地址,可能导致具有有效会话cookie或经过身份验证的浏览器的攻击者更改账户电子邮件,从而控制账户恢复并绕过多因素身份验证保护。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: email changed victim@capgo.app -> attacker@evil.com with session cookie only (no current_password/MFA); proof flag exfiltrated: PROOF_51d92317568c8be2
| CVE-2026-56241 | 8.3 HIGH | Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right |
| CVE-2026-56313 | 8.1 HIGH | Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint |
| CVE-2026-56238 | 7.5 HIGH | Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint |
| CVE-2026-56252 | 5.4 MEDIUM | Capgo - Scope Isolation Failure in Webhook Test Endpoint |
| CVE-2026-56336 | 5.3 MEDIUM | Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint |
| CVE-2026-56281 | 3.8 LOW | Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint |
No comments yet