CVE-2026-56228

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum password length, making compliance impossible for all organization members. Once the policy is enabled, users (including administrators) are unable to change their passwords or access the organization, resulting in an organization-wide account lockout and application-level denial of service.
Configurations

No configuration.

History

20 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-20 16:17

Updated : 2026-06-23 15:16


NVD link : CVE-2026-56228

Mitre link : CVE-2026-56228

CVE.ORG link : CVE-2026-56228


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation