SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-56305

HIGH · CVSS 8.3 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

An authentication bypass vulnerability in Capgo versions prior to 12.128.2 allows attackers to change user passwords via the password change endpoint without needing current password confirmation. This flaw can lead to permanent account lockout for legitimate users and full account takeover by malicious actors with temporary session access. Organizations using affected versions should prioritize immediate patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56305
Severity
HIGH
CVSS
8.3
EPSS
0.36%

Original NVD Description

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.