CVE-2026-53981 Details
Description
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanently take over the victim's account.
A vulnerability allowing account takeover has been identified in Cap-go versions prior to 12.128.2. This issue arises from the email change mechanism, which allows an attacker with temporary authenticated session access to change the registered email address without requiring re-authentication, such as password or multi-factor authentication verification. Exploitation of this vulnerability enables attackers to redirect verification to an email address they control, allowing them to perform a password reset and permanently take over the victim's account.
Users can update to Cap-go version 12.128.2, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-w56g-jv78-hf79 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Cap-go/capgo/commit/6685e5f11adef257bf3d085e481f4d8ebcec602e | [email protected] | Source CodeVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-w56g-jv78-hf79 | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/cap-go-account-takeover-via-unauthenticated-email-change-mechanism | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cap-go | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion