VDB
CVE-2026-30943
CVE-2026-30943
PUBLISHED
CVSS 4.099999904632568 MEDIUM
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.
EPSS 0.01% · 1.3th percentile
Risk Scores
CVSS v3.1
4.099999904632568
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.01%
1.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forceu | Gokapi | < 2.2.4, < 2.2.4 |
| github.com | forceu/gokapi | 0, 0 |
| forceu | gokapi | 0, 0 |
Timeline
- Mar 13, 2026 CVE Published
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
- Mar 17, 2026 Security Advisory
- Mar 18, 2026 EPSS Score
- Mar 19, 2026 EPSS Score
- Mar 20, 2026 EPSS Score
- Mar 21, 2026 EPSS Score
- Mar 22, 2026 EPSS Score