CVE-2026-53868 PUBLISHED

Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 12.06.2026 Updated: 12.06.2026

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can permanently lock legitimate users out of the platform for 30 days by exploiting unverified email ownership in account lifecycle operations.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Capgo
Product Capgo
Versions Default: unaffected
  • affected from 0 to 12.128.2 (excl.)
  • Version 12.128.2 is unaffected

Credits

  • Naitik Gupta reporter

References

Problem Types

  • Missing Authentication for Critical Function CWE