CVE-2026-56215 PUBLISHED

Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning

Assigner: VulnCheck
Reserved: 19.06.2026 Published: 20.06.2026 Updated: 20.06.2026

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim's corporate SSO email, causing the provision-user endpoint to merge the victim's SSO identity into the attacker-controlled account.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Capgo
Product Capgo
Versions Default: unaffected
  • affected from 0 to 12.128.12 (excl.)
  • Version 12.128.12 is unaffected

Credits

  • Judel777 reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE