CVE-2026-56312

Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted accounts and burn invite links.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-10 15:16

Updated : 2026-07-10 17:17


NVD link : CVE-2026-56312

Mitre link : CVE-2026-56312

CVE.ORG link : CVE-2026-56312


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication