Credential Validation Vulnerability in Capgo from Capgo
CVE-2026-56234

6.9MEDIUM

Key Information:

Vendor

Capgo

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-56234?

Capgo versions before 12.128.2 are susceptible to a credential validation vulnerability in the /functions/v1/private/validate_password_compliance endpoint. This endpoint can be invoked using only the public Supabase key without requiring authentication. The lack of proper access control, coupled with CORS-permissive settings that allow any origin, and the absence of rate limiting, opens the door for attackers to exploit the system. Attackers can leverage this vulnerability to execute password spraying and credential stuffing attacks, posing a significant risk to user account security.

Affected Version(s)

Capgo 0 < 12.128.2

Capgo 12.128.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.