CVE-2026-56223: Capgo Cross-Domain Account Takeover via SAML Assertion Forgery
Capgo versions before 12.128.2 have a critical account takeover flaw in their user provisioning system. An attacker with admin access to an enterprise organization can trick the system into merging victim accounts by forging identity provider assertions. This happens because the system doesn't properly verify that the identity provider making the request is authorized to provision users for the victim's domain. Once merged, the attacker gains complete control of the victim's account, organization, and all associated data.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.7 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
- Weaknesses (CWE)
- CWE-287
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-24 / 2026-06-25
NVD description (verbatim)
Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authorization. An attacker with enterprise org admin access and a malicious IdP can forge SAML assertions containing victim email addresses to trigger account merge and gain full access to victim accounts, organizations, and data.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-56223 is an improper authentication vulnerability (CWE-287) in Capgo's provision-user endpoint that fails to validate SSO provider domain authorization. The vulnerability allows attackers with enterprise organization admin credentials to exploit SAML assertion forgery. By sending crafted SAML assertions containing victim email addresses to the provision-user endpoint, an attacker can trigger cross-domain account merges without proper domain ownership validation. The absence of authorization checks on which domains an IdP is permitted to provision users for enables account consolidation attacks that grant the attacker full account access, organization membership, and data visibility for victim accounts.
Business impact
Successful exploitation enables complete account takeover of individual users and organizations within Capgo. Attackers can access sensitive organizational data, modify configurations, and perform actions on behalf of compromised accounts. For enterprises using Capgo for critical application management or deployment orchestration, this represents loss of confidentiality and integrity of their entire operational environment. The attack requires admin-level access to a federated organization, making it a particularly severe insider threat vector and a risk for multi-tenant SaaS environments where one compromised admin can attack users across multiple customer organizations.
Affected systems
Capgo versions prior to 12.128.2 are affected. The vulnerability exists in the provision-user endpoint and impacts any Capgo deployment using SAML-based single sign-on with federated enterprise organizations. Organizations relying on Capgo for app deployment, release management, or CI/CD integration should prioritize verification of their installed version.
Exploitability
Exploitation requires high privilege level (enterprise organization admin access) and a malicious or compromised identity provider under attacker control. The attack is network-accessible with no user interaction required from victims. While the privilege requirement is high, the barrier to exploitation is relatively low once an attacker has obtained or controls an IdP—SAML assertion forgery is straightforward, and the vulnerable endpoint accepts the malicious requests without validation. Organizations with federated SSO and multiple admin accounts face meaningful risk.
Remediation
Upgrade Capgo to version 12.128.2 or later. This patch addresses the domain authorization validation gap in the provision-user endpoint, ensuring that identity providers can only provision users for domains they are explicitly authorized to manage. Verify the upgrade was successful by confirming the installed version and, where applicable, monitoring for any unexpected account merges or permission changes in audit logs.
Patch guidance
Apply Capgo update 12.128.2 or later to all affected deployments. Verify against the official Capgo release notes and vendor advisory for any prerequisites or post-patch validation steps. Organizations should test the patch in a staging environment to confirm compatibility with existing SAML configurations before production deployment. After patching, conduct a retrospective audit of user accounts and organization memberships to detect any unauthorized account merges that may have occurred.
Detection guidance
Monitor Capgo's provision-user endpoint access logs and SAML assertion handling for anomalies, including provision requests from IdPs attempting to merge accounts across different email domains. Alert on admin API calls to the provision-user endpoint combined with unusual account merge activity. Review federation trust relationships and confirm that only expected IdPs are configured for account provisioning. Cross-reference user merge events with known legitimate provisioning flows and organizational changes. Check for any accounts that were merged without corresponding legitimate SSO domain changes.
Why prioritize this
This vulnerability merits immediate attention due to its high CVSS score (8.7), direct path to account takeover, and broad organizational blast radius. The ability to merge accounts across domain boundaries means a single compromised admin plus a malicious IdP can compromise multiple user accounts and entire organizations. The absence of KEV status does not diminish urgency—the technical severity and ease of exploitation once prerequisites are met demand swift patching. Organizations should treat this as a critical security incident risk and prioritize Capgo updates accordingly.
Risk score, explained
CVSS 8.7 (HIGH) reflects a network-accessible attack with high privilege requirements but no user interaction needed, affecting multiple attack vectors (confidentiality, integrity, and scope). The score captures the severe impact—complete account takeover—balanced against the prerequisite of admin-level access and a malicious IdP. For organizations with robust IdP security controls and limited admin accounts, risk may trend lower; for those with federated multi-admin setups, risk is substantially higher.
Frequently asked questions
Do we need to be using SAML-based SSO for this to affect us?
Yes. The vulnerability specifically exploits SAML assertion handling in the provision-user endpoint. Organizations using Capgo without federated SSO or using non-SAML authentication methods are not affected by this particular flaw.
If we've patched to 12.128.2, do we need to audit past account activity?
Yes. We recommend a post-patch audit of account merge history and user organization memberships to detect any unauthorized account consolidations that may have occurred before the patch was deployed. If you find suspicious account merges, consider resetting credentials and reviewing access logs for those accounts.
What if one of our IdP administrators has been compromised?
An attacker with control of your IdP could exploit this vulnerability to forge SAML assertions and merge arbitrary accounts. This highlights the importance of securing your identity provider infrastructure separately. Even after patching Capgo, a compromised IdP remains a critical security incident requiring immediate containment and credential rotation.
Does this affect our supply chain if we use Capgo internally?
If you use Capgo for application deployment or release management, a successful account takeover could grant an attacker the ability to deploy malicious code, modify releases, or access sensitive build artifacts. Patching should be treated as a supply chain integrity priority.
This analysis is provided for informational purposes and represents our assessment based on the publicly disclosed vulnerability details. Verify all version numbers, patch applicability, and remediation steps against official Capgo vendor advisories and release notes. CVSS scores are provided by the source data and subject to interpretation based on organizational context. Security testing or exploitation of this vulnerability without explicit authorization is illegal. Organizations should conduct their own risk assessment and compliance review before implementing patches or changes to production systems. Source: NVD (public-domain), retrieved 2026-07-30. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-10157HIGHOpen5GS NGAP Authentication Bypass Vulnerability – 5G Core Network Risk
- CVE-2026-10167HIGHAuthentication Bypass in BrinaryBrains School Management System
- CVE-2026-10243HIGHSmart Parking System 1.0 Authentication Bypass – Remote Admin Access
- CVE-2026-10281HIGHEnderfga claw-orchestrator Authentication Bypass – Patch Available
- CVE-2026-10288HIGHHotel Reservation System Admin Authentication Bypass
- CVE-2026-10617HIGHGoClaw Webhook Authentication Bypass – Remote Exploitation
- CVE-2026-10619HIGHsayan365 Student-Management-System Remote Authentication Bypass
- CVE-2026-10777HIGHealpha072 Student-Management-System Authentication Bypass in Admin Backend