PT-2026-23602 · Gokapi · Gokapi

Sijisu

·

Published

2026-03-05

·

Updated

2026-03-25

·

CVE-2026-28682

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gokapi versions prior to 2.2.3
Description Gokapi is a self-hosted file sharing server that supports automatic expiration and encryption. The upload status Server-Sent Events (SSE) implementation on the /uploadStatus API endpoint publishes global upload state to any authenticated user and includes file id values that are not limited to the requesting user. This can lead to cross-tenant data exposure and loss of confidentiality for uploaded documents, as authenticated users can observe other users' file identifiers and retrieve unauthorized content.
Recommendations Update to version 2.2.3 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28682
GHSA-C36C-7PC2-F2PH
GO-2026-4613
SUSE-SU-2026:1042-1

Affected Products

Gokapi