CVE Feed

    Dashboard / CVE / CVE-2026-56223

    CVE-2026-56223

    Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authorization. An attacker with enterprise org admin access and a malicious IdP can forge SAML assertions containing victim email addresses to trigger account merge and gain full access to victim accounts, organizations, and data.

    Published:Jun 24, 2026
    Last Modified:Jun 24, 2026
    EPS:Jun 24, 2026
    EPSS Score:
    CVSS Score:8.7

    Affected Products

    Vendor
    Cap-go
    Product
    Cap-go

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High