CVE-2026-56073
Received Received - Intake
Authentication Bypass in Cap-go via OTP Response Manipulation

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: VulnCheck

Description
Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA enablement and account takeover.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-20
AI Q&A
2026-06-20
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Cap-go versions before 12.128.2 and involves an authentication bypass in the OTP (One-Time Password) verification process.

Attackers can intercept OTP verification requests and manipulate the server's HTTP responses to falsely indicate that the OTP verification was successful.

This allows attackers to bypass email verification, enabling unauthorized enabling of two-factor authentication (2FA) and potentially taking over user accounts.

Impact Analysis

The vulnerability can lead to unauthorized account takeover by allowing attackers to bypass OTP email verification.

Attackers can enable 2FA on accounts without the legitimate user's consent, potentially locking out the rightful owner and gaining unauthorized access.

This compromises account security and can lead to data breaches, loss of sensitive information, and unauthorized actions performed under the victim's identity.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56073. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart