CVE-2026-56286
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-56286, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-06-30

Assigner: VulnCheck

Description

Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authentication or secondary verification. Attackers can delete user accounts via session hijacking, CSRF attacks, or parameter tampering, resulting in unauthorized account deletion, data loss, and denial-of-service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-06-30
Generated
2026-07-01
AI Q&A
2026-07-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
capgo capgo to 12.128.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Capgo versions before 12.128.2 and involves an authentication bypass in the account deletion endpoint.

It allows attackers to delete user accounts without requiring password re-authentication or secondary verification.

Attackers can exploit this vulnerability through session hijacking, Cross-Site Request Forgery (CSRF) attacks, or parameter tampering.

As a result, unauthorized account deletion can occur, leading to data loss and denial-of-service conditions.

Impact Analysis

This vulnerability can have serious impacts including unauthorized deletion of user accounts.

Such unauthorized deletions can cause loss of important user data.

Additionally, it can lead to denial-of-service by disrupting normal account operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56286. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart