CVE Feed

    Dashboard / CVE / CVE-2026-53981

    CVE-2026-53981

    Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanently take over the victim's account.

    Published:Jun 12, 2026
    Last Modified:Jun 12, 2026
    EPS:Jun 12, 2026
    EPSS Score:
    CVSS Score:7.6

    Affected Products

    Vendor
    Cap-go
    Product
    Cap-go

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High