← Zurück zur CVE-Suche

CVE-2026-56212

Beschreibung

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to verify the initiator-s 2FA status before allowing the policy change, resulting in inconsistent security enforcement, potential administrative misuse, and lockout risk for team members.

CVSS 3.8EPSS 0.34199999999999997%Risiko 0.39
Quelle öffnen
Veröffentlicht
2026-06-20 01:16:16
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N