Back to CVE List

CVE-2026-56338

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Vulnerability Description

Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authenticated users cannot complete 2FA enrollment as the backend consistently returns HTTP 500 errors with captcha verification process failed messages, blocking access to security controls.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-703
Source
NVD
Vendor
Capgo
Product
Capgo

External References

Discussion (0)

Add Comment

No comments yet. Be the first!