CVE-2026-30943

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:*

History

17 Mar 2026, 13:48

Type Values Removed Values Added
CPE cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:*
First Time Forceu
Forceu gokapi
References () https://github.com/Forceu/Gokapi/releases/tag/v2.2.4 - () https://github.com/Forceu/Gokapi/releases/tag/v2.2.4 - Product, Release Notes
References () https://github.com/Forceu/Gokapi/security/advisories/GHSA-j6jp-78w8-34x6 - () https://github.com/Forceu/Gokapi/security/advisories/GHSA-j6jp-78w8-34x6 - Vendor Advisory

13 Mar 2026, 19:54

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:54

Updated : 2026-03-17 13:48


NVD link : CVE-2026-30943

Mitre link : CVE-2026-30943

CVE.ORG link : CVE-2026-30943


JSON object : View

Products Affected

forceu

  • gokapi
CWE
CWE-863

Incorrect Authorization