CVE-2026-56314: high-severity vulnerability in Capgo
Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Affected products
Capgo · CapgoRelated CVEs — Capgo
In the same product, most dangerous first.
CVE-2026-56299MEDIUMCapgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload EndpointEPSS 0.7%CVE-2026-56323HIGHCapgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_selfEPSS 0.6%CVE-2026-56233HIGHCapgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload ProxyEPSS 0.6%CVE-2026-56238HIGHCapgo - Unauthenticated Information Disclosure via PostgREST global_stats EndpointEPSS 0.6%CVE-2026-56286HIGHCapgo - Account Deletion Without Password ConfirmationEPSS 0.5%CVE-2026-56222HIGHCapgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindingsEPSS 0.5%