CVE-2026-56338
Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authenticated users cannot complete 2FA enrollment as the backend consistently returns HTTP 500 errors with captcha verification process failed messages, blocking access to security controls.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.49%
- CWE
- CWE-703
- Published
- 2026-06-24
- Last modified
- 2026-06-24
Affected products
- Capgo Capgo
- Capgo Capgo
Weakness type
Related vulnerabilities
- CVE-2026-80135 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-57445 — Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
- CVE-2026-20280 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-82417 — qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
- CVE-2026-18638 — Velociraptor server crash via the SetPassword API
- CVE-2026-56818 — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
- CVE-2026-16218 — hunvreus devpush Storage Reset Failure storage.py reset_storage improper check or handling of exceptional conditions
- CVE-2026-20187 — Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities