Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA enablement and account takeover.
References
Configurations
No configuration.
History
22 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Cap-go/capgo/security/advisories/GHSA-x2gq-85v8-j9v4 - |
19 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-19 22:16
Updated : 2026-06-22 19:49
NVD link : CVE-2026-56073
Mitre link : CVE-2026-56073
CVE.ORG link : CVE-2026-56073
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity
