SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-56312

MEDIUM · CVSS 6.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

An improper validation vulnerability in Capgo allows attackers to bypass captcha protection on the accept_invitation endpoint, enabling the creation of user accounts without proper validation. This can lead to unauthorized account creation and potential abuse of invite links. Organizations using affected versions of Capgo should prioritize patching to mitigate the risk of account spoofing and associated security issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56312
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted accounts and burn invite links.