Descrição
Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim-s email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim-s identity, allowing them to read and modify its state and enforce organization-level policies, while the legitimate user is denied access to the account tied to their own email.
CVSS 9.1EPSS 0.5740000000000001%Risco 0.96
Ver fonte- Publicação
- 2026-06-19 22:16:18
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N