Authentication Bypass in Cap-go's OTP Verification Process
CVE-2026-56073

9.3CRITICAL

Key Information:

Vendor

Cap-go

Status
Vendor
CVE Published:
19 June 2026

What is CVE-2026-56073?

Cap-go versions prior to 12.128.2 exhibit a vulnerability that allows attackers to bypass email verification through manipulation of OTP verification processes. This issue arises when attackers intercept OTP requests, subsequently modifying HTTP responses to incorrectly indicate that the verification has succeeded. As a result, unauthorized users may enable two-factor authentication (2FA) on accounts without proper verification, leading to potential account takeover and significant implications for user security.

Affected Version(s)

capgo 0 < 12.128.2

capgo 12.128.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nancyhunter191
.