6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert, and delete stored app icons. Remote attackers can exploit this misconfiguration to delete all icons and leak sensitive app IDs and user IDs.
Basic Information
ID
CVE-2026-56302
Source
VulnCheck
Published
Jun 24, 2026 at 11:53
Affected Product
Vendor
Capgo
Product
Capgo
Affected Versions
Capgo Capgo 0