← Retour à la recherche de CVE

CVE-2026-56313

Capgo

Description

Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider-s email domain, forcing victims to use the attacker-s SSO provider or complete password reset recovery.

CVSS 8.1EPSS 0.27599999999999997%Risque 0.83
Voir la source
Publication
2026-07-12 12:16:45
Versions concernées
<12.128.2
Type
Logiciel critique
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H