Mehrere Schwachstellen (CVE-2026-45480, CVE-2026-48582, CVE-2026-48584, CVE-2026-48772, CVE-2026-48773, CVE-2026-50242, CVE-2026-56073, CVE-2026-56081, CVE-2026-56265, CVE-2026-56395, CVE-2026-56397) in Cap-Go
⚠️ CVE-Referenzen:
CVE-2026-45480
CVE-2026-48582
CVE-2026-48584
CVE-2026-48772
CVE-2026-48773
CVE-2026-50242
CVE-2026-56073
CVE-2026-56081
CVE-2026-56265
CVE-2026-56395
CVE-2026-56397
Cap-go - Capgo - CRITICAL - CVE-2026-56081.
Cap-go, prior to version 12.128.2, possesses a significant authentication logic flaw that permits attackers to register and seize control of an account tied to a user's email address before email verification is completed. This vulnerability enables the attacker to activate two-factor authentication (2FA) on an account that appears to belong to the victim, allowing unauthorized access to sensitive account information and modification capabilities while the legitimate user is effectively locked out under their own credentials.
Quelle: securityvulnerability.io