Unrated severityNVD Advisory· Published Jun 20, 2026
Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning
CVE-2026-56215
Description
Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim's corporate SSO email, causing the provision-user endpoint to merge the victim's SSO identity into the attacker-controlled account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-wqc6-fhwf-qpwwmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-account-merge-via-poisoned-public-users-email-in-sso-provisioningmitrethird-party-advisory
News mentions
2- Capgo: 21 CVEs Disclosed Together — Unauthenticated Cross-Tenant Bugs and Scope Escalation Lead the BatchVypr Intelligence · Jun 20, 2026
- Capgo: Ten Vulnerabilities Disclosed Together, Including Scope Escalation and Unauthenticated Cross-Tenant BugsVypr Intelligence · Jun 20, 2026