CVE-2026-53982 Details
Description
Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to be redirected to an account-disabled page for approximately 30 days, preventing any account login or registration from that device.
A denial-of-service vulnerability has been identified in Capgo Console versions prior to 12.28.2. The issue arises in the account deletion process, where the platform mistakenly links the deletion status to the device identifier of the active session. This misassociation causes the affected device or browser to be redirected to an account-disabled page for about 30 days, blocking any login or registration attempts from that device.
Users can update to Capgo Console version 12.128.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/commit/6685e5f11adef257bf3d085e481f4d8ebcec602e | [email protected] | Source CodeVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-qmrm-qgwr-55jf | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/capgo-console-account-deletion-dos-via-device-identifier-association | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-645 | Overly Restrictive Account Lockout Mechanism | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Capgo Console | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 13, 2026 | CVE Modified | [email protected] |
| Jun 12, 2026 | CVE Modified | [email protected] |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion