CVE 8.7 HIGH

Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion_CVE-2026-53868

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can permanently lock legitimate users out of the platform for 30 days by exploiting unverified email ownership in account lifecycle operations.

AI Analysis

Denial of Service via Unverified Email Account Registration and Deletion

Basic Information

ID CVE-2026-53868
Source VulnCheck
Published Jun 12, 2026 at 21:57

Affected Product

Vendor Capgo
Product Capgo
Affected Versions Capgo Capgo 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Capgo
Product Capgo
Version < 12.128.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.