Credential Validation Vulnerability in Capgo from Capgo
CVE-2026-56234
6.9MEDIUM
What is CVE-2026-56234?
Capgo versions before 12.128.2 are susceptible to a credential validation vulnerability in the /functions/v1/private/validate_password_compliance endpoint. This endpoint can be invoked using only the public Supabase key without requiring authentication. The lack of proper access control, coupled with CORS-permissive settings that allow any origin, and the absence of rate limiting, opens the door for attackers to exploit the system. Attackers can leverage this vulnerability to execute password spraying and credential stuffing attacks, posing a significant risk to user account security.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
