Unrated severityNVD Advisory· Published Jun 19, 2026
Cap-go - OTP Bypass via Response Manipulation in Email Verification
CVE-2026-56073
Description
Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA enablement and account takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-x2gq-85v8-j9v4mitrevendor-advisory
- www.vulncheck.com/advisories/cap-go-otp-bypass-via-response-manipulation-in-email-verificationmitrethird-party-advisory
News mentions
2- Capgo: 21 CVEs Disclosed Together — Unauthenticated Cross-Tenant Bugs and Scope Escalation Lead the BatchVypr Intelligence · Jun 20, 2026
- Capgo: Ten Vulnerabilities Disclosed Together, Including Scope Escalation and Unauthenticated Cross-Tenant BugsVypr Intelligence · Jun 20, 2026