SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-56309

MEDIUM · CVSS 5.4 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Capgo versions prior to 12.128.2 are vulnerable due to inadequate enforcement of plan and quota restrictions on the /files/upload/attachments endpoint, allowing unauthorized apps to create publicly accessible R2 objects. This flaw enables attackers to upload arbitrary files using upload-scoped API keys, leading to potential storage and bandwidth abuse, as these objects can persist even after app deletion. Organizations using Capgo should prioritize patching this vulnerability to mitigate the risk of unauthorized data exposure and resource exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56309
Severity
MEDIUM
CVSS
5.4
EPSS
0.26%

Original NVD Description

Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist outside normal bundle metadata, and survive app deletion, enabling storage and bandwidth abuse.