SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-56283

MEDIUM · CVSS 5.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability in Capgo versions prior to 12.128.2 allows for HTML injection through the organization settings endpoint, enabling attackers to manipulate the organization name field. This can lead to phishing attacks by redirecting users to untrusted websites, posing a risk of reputational damage. Organizations using affected versions should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56283
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML content. Attackers can craft payloads in the organization name field to redirect users to untrusted websites, enabling phishing attacks and reputational damage.