CVE-2026-56080: Capgo Password Policy Enforcement Bug Causes Super Admin Lockout
Capgo versions before 12.128.2 have a bug in their password policy enforcement system. When a Super Admin enables the Enforce Password Policy feature and changes their password to meet the requirements, the system incorrectly continues to treat the account as non-compliant. This causes the backend to repeatedly force password reset prompts, effectively locking the Super Admin out of their organization—even though their credentials are valid. The result is a denial of service affecting administrative access.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.9 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-287
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-19 / 2026-06-24
NVD description (verbatim)
Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat the account as non-compliant and repeatedly forces password-reset prompts, permanently locking the Super Admin out of organization access (organization lockout / denial of service) despite valid authentication.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from a state-synchronization failure in Capgo's password compliance verification logic. When the Enforce Password Policy feature is activated and a Super Admin successfully changes their password to a compliant value, the backend's password-compliance state machine does not update. Consequently, subsequent authentication attempts trigger persistent password-reset enforcement, creating an authentication loop that denies access to organization resources. The root cause is classified under CWE-287 (Improper Authentication), indicating that the backend's validation of password compliance does not correctly reflect the actual compliance state after a valid password change.
Business impact
This vulnerability directly threatens administrative continuity and organizational availability. Super Admins managing Capgo deployments who enable the password policy feature risk permanent lockout from their organization, with no straightforward recovery path during the window before patching. The impact escalates in organizations with single Super Admin accounts or limited administrative redundancy. While the vulnerability requires High privilege to trigger (the Super Admin must enable the policy themselves), the consequence—complete loss of administrative access—is severe enough to warrant immediate remediation before policy activation.
Affected systems
Capgo versions prior to 12.128.2 are affected. The vulnerability is triggered only after a Super Admin explicitly enables the Enforce Password Policy feature, meaning organizations that have not yet activated this feature are not exposed to the immediate risk. However, any deployment planning to enable password policies should upgrade before doing so.
Exploitability
Exploitation requires High privilege (Super Admin credentials) and is entirely network-accessible. No user interaction is needed beyond the Super Admin's intentional password change to comply with the policy. The attack surface is therefore limited to Super Admin accounts within organizations using Capgo, and the vector is straightforward: enable policy, change password to compliant value, and observe the lockout. The low complexity and high-privilege requirement mean exploitation is unlikely from external threat actors but poses a significant operational risk to administrators managing their own deployments.
Remediation
Upgrade Capgo to version 12.128.2 or later. This patch corrects the backend's password-compliance state tracking, ensuring that after a valid compliant password change, the account is properly marked as compliant and no further password-reset prompts are issued. Organizations should apply the patch before enabling the Enforce Password Policy feature, or if the feature is already active and a Super Admin is locked out, the patch should be prioritized for immediate deployment.
Patch guidance
Deploy Capgo 12.128.2 or later in your environment. If a Super Admin is currently locked out due to this issue, the patch will resolve the persistent reset-prompt loop upon deployment and re-authentication. Verify the patch version in your release notes or vendor documentation to confirm the fix is included. Consider staging the upgrade in a test environment first if your deployment allows, then roll out to production. After patching, affected Super Admins should be able to authenticate and access their organization normally.
Detection guidance
Monitor Capgo audit logs for repeated password-reset prompts originating from the same Super Admin account in a short time window, particularly following an Enforce Password Policy activation. A Super Admin repeatedly triggering or receiving password-reset enforcement despite having recently changed their password is an indicator of this issue. Operational indicators include Super Admin lockout reports immediately after enabling the password policy feature and failed authentication attempts cycling back to password-reset screens. Cross-reference enabled features in your Capgo configuration to identify if password policy enforcement is active.
Why prioritize this
Although the CVSS score is 4.9 (MEDIUM), the vulnerability merits high prioritization in practice due to the administrative context. Loss of Super Admin access to an organization is operationally critical, regardless of the numeric severity rating. The fix is straightforward (upgrade to 12.128.2), and the window of exposure is limited to organizations actively using the password policy feature. Prioritize upgrading any Capgo deployment in which the Enforce Password Policy feature is currently or imminently enabled.
Risk score, explained
The CVSS 3.1 score of 4.9 reflects a MEDIUM severity: Network-accessible (AV:N), Low attack complexity (AC:L), High privilege required (PR:H), no user interaction needed (UI:N), no scope change (S:U), no confidentiality or integrity impact (C:N, I:N), but High availability impact (A:H). The High availability impact accounts for the denial-of-service nature of the lockout. The score appropriately weights the privilege requirement (limiting external attack surface) against the severity of the outcome (organizational lockout). However, in a risk context, administrative access denial may warrant higher operational priority than the numeric score alone suggests.
Frequently asked questions
Can this vulnerability be exploited without Super Admin credentials?
No. The vulnerability requires a Super Admin to enable the Enforce Password Policy feature and initiate a password change. External threat actors cannot trigger this issue without already holding Super Admin privileges to Capgo.
If a Super Admin is locked out, what is the recovery procedure before patching?
The source data does not specify a manual recovery procedure. Organizations should prioritize applying patch version 12.128.2 as the primary recovery path. Contact Capgo support if an alternative recovery method is needed before the patch can be deployed.
Do I need to enable the password policy feature for this vulnerability to affect my organization?
Yes. The vulnerability is only triggered when a Super Admin explicitly enables the Enforce Password Policy feature in their Capgo instance. If your organization has not enabled this feature, you are not currently exposed to this specific issue, though upgrading remains a best practice.
What happens after I upgrade to 12.128.2 if a Super Admin is currently locked out?
After the patch is deployed, the backend's password-compliance state tracking will be corrected. Upon re-authentication, the Super Admin should no longer experience repeated password-reset prompts and should regain normal access to their organization.
This analysis is based on published vulnerability data and vendor advisories as of the modification date. CVSS scores and severity ratings are provided by the CVE system and reflect standardized metrics; operational risk may differ. No working exploit code or detailed attack steps are provided. Organizations should verify patch applicability and test in non-production environments before deployment. For the most current information, consult the official Capgo security advisories and your vendor support channel. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2023-5502MEDIUMArista EOS 802.1x Authentication Bypass Vulnerability
- CVE-2026-10283MEDIUMBottelet DaybydayCRM Authentication Bypass in Settings Handler
- CVE-2026-10548MEDIUMImproper Authentication in NousResearch hermes-agent Credential Synchronization
- CVE-2026-34917MEDIUMSession Reuse Privilege Escalation in Web Console and XML-RPC API
- CVE-2026-35261MEDIUMOracle Access Manager Authentication Bypass (CVSS 6.5)
- CVE-2026-40995MEDIUMSpring Web Services X509 Authentication Bypass Accounting Lifecycle Checks
- CVE-2026-45153MEDIUMNextcloud Android Files App PIN Bypass via Back Button
- CVE-2026-45283MEDIUMNextcloud File Lock Authorization Bypass