CVE-2026-53982: Cap-go Console Account Deletion DoS Vulnerability (CVSS 6.5)
Cap-go Console versions before 12.28.2 contain a flaw that allows attackers with valid account credentials to trigger a denial-of-service condition affecting device authentication. When an attacker initiates account deletion while a device identifier is active in a session, the platform incorrectly locks that device to a disabled-account page for approximately 30 days. This prevents legitimate users from logging in or creating new accounts on that device or browser, even if they own the account or are attempting to register fresh.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-645
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-12 / 2026-06-17
NVD description (verbatim)
Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to be redirected to an account-disabled page for approximately 30 days, preventing any account login or registration from that device.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in Cap-go Console's account deletion logic, which fails to properly segregate deletion state from device identifiers. The flaw manifests as a state-association error (CWE-645) where the platform binds the account-deleted flag to the device/browser environment rather than user identity. An authenticated attacker can exploit this by initiating account deletion with an active device session, causing the deletion state to persist at the device level. The affected device is then redirected to an account-disabled page for approximately 30 days, blocking all authentication and registration flows originating from that environment. This is a logic defect rather than a cryptographic or injection-based vulnerability.
Business impact
Organizations relying on Cap-go Console for device provisioning, onboarding, or account management face service disruption affecting end-user productivity. If an attacker compromises an account with user credentials, they can deny legitimate users access from shared or corporate devices for roughly a month. For organizations managing fleets of devices or supporting bring-your-own-device (BYOD) scenarios, widespread exploitation could disrupt onboarding pipelines and create friction in device authentication workflows. The 30-day lockout window is particularly disruptive for time-sensitive onboarding processes.
Affected systems
Cap-go Console versions prior to 12.28.2 are affected. The vulnerability requires authenticated access (PR:L in the CVSS vector), meaning the attacker must possess valid account credentials. Any device or browser environment linked to an active session during exploitation is susceptible to the 30-day lock-out condition.
Exploitability
Exploitability is moderate. The attack requires low-privilege authenticated access (valid account credentials) and no user interaction beyond triggering account deletion. The attack surface is network-based (AV:N) with low attack complexity (AC:L), making exploitation straightforward for any user with a Cap-go Console account. However, the impact is localized to the device or browser performing the deletion request, limiting the blast radius of a single attack. Systematic exploitation would require either multiple compromised accounts or coordinated attacks on targeted devices.
Remediation
Upgrade Cap-go Console to version 12.28.2 or later. This version corrects the state-association logic to bind account deletion state to user identity rather than device identifiers, eliminating the device-level lock-out condition. Verify the upgrade is applied across all Cap-go Console instances in your environment, including any self-hosted or on-premises deployments.
Patch guidance
Apply the upgrade to Cap-go Console 12.28.2 or newer as soon as possible. Prioritize patching in environments where account takeover or credential compromise is a concern, as these increase the likelihood of exploitation. Test the patch in a non-production environment first to confirm compatibility with dependent onboarding and authentication workflows. No workarounds are available; patching is the only remediation.
Detection guidance
Monitor for patterns of repeated account deletion attempts, particularly those initiated from the same device or IP address in short time windows. Log account deletion events paired with session identifiers and device identifiers to detect attempts to lock out devices systematically. Watch for user complaints about repeated authentication failures from specific devices despite valid credentials—this is a behavioral indicator of exploitation. Audit access logs for high-velocity deletion requests from low-privilege accounts, which may suggest credential compromise combined with exploitation attempts.
Why prioritize this
This is a medium-severity vulnerability (CVSS 6.5) that should be addressed in routine patch cycles but does not require emergency response. While the impact on availability is high (A:H in the vector), the requirement for authenticated access limits exposure. Prioritize patching if your organization supports high-volume device onboarding, shared device environments, or BYOD scenarios where the 30-day lock-out would cause significant operational friction. Lower priority for small teams with dedicated device management and strong credential hygiene.
Risk score, explained
The CVSS 3.1 score of 6.5 (MEDIUM) reflects a vulnerability with high availability impact but constrained exploitability. The requirement for authenticated access (PR:L) prevents unauthenticated exploitation, reducing the attack surface. Network-based delivery (AV:N) and low complexity (AC:L) make exploitation trivial once credentials are obtained, but the scope is unchanged (S:U), meaning the impact does not cross trust boundaries. The 30-day lock-out duration amplifies the availability harm, yet the device-level localization prevents organization-wide outages from a single attack. This profile—limited exposure, moderate impact, narrow scope—justifies a MEDIUM rating.
Frequently asked questions
Can an unauthenticated attacker exploit this vulnerability?
No. The vulnerability requires valid Cap-go Console account credentials (authenticated access). An attacker must obtain or compromise a user account to trigger the flaw. This requirement significantly reduces the exposure compared to unauthenticated denial-of-service vulnerabilities.
How long does a device remain locked after exploitation?
Approximately 30 days. After that period, the lock-out condition expires and the device can authenticate normally. However, this extended lock-out window is disruptive for active users and can derail time-sensitive onboarding workflows. Patching is necessary to avoid the 30-day disruption entirely.
Does this vulnerability affect other Cap-go products?
The vulnerability is specific to Cap-go Console versions prior to 12.28.2. Verify the version of Cap-go Console in your environment and cross-reference with the vendor's advisory to confirm whether other Cap-go offerings are affected. Only Cap-go Console is mentioned in the available advisory data.
Can an attacker lock out all devices in an organization with a single attack?
No. The vulnerability is localized to the device or browser environment in which the deletion request is initiated. Locking out multiple devices would require either multiple compromised accounts or coordinated attacks against different devices. This limits the blast radius of exploitation but does not eliminate risk in environments with weak credential management.
This analysis is based on vulnerability information published as of June 2026. Security advisories and patch availability may evolve; verify all patch versions and guidance directly with Cap-go's official advisory and documentation. This page is for informational purposes and does not constitute professional security advice. Organizations should assess risk in the context of their specific deployments, threat model, and compliance requirements. Consult with Cap-go support and your security team before applying patches to production environments. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20064MEDIUMWP Vault 0.8.6.6 Arbitrary File Read via Directory Traversal
- CVE-2016-20067MEDIUMWordPress CP Polls CSRF Vulnerability
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2016-20074MEDIUMWordPress Lazy Content Slider CSRF Vulnerability – Patch & Detection Guide
- CVE-2016-20077MEDIUMWordPress Photocart Link Plugin Local File Inclusion Vulnerability
- CVE-2016-20078MEDIUMWordPress IMDb Profile Widget Local File Inclusion Vulnerability
- CVE-2016-20079MEDIUMWordPress Dharma Booking Local File Inclusion Vulnerability
- CVE-2016-20080MEDIUMWordPress Brandfolder Plugin LFI Vulnerability – File Disclosure & Remediation Guide