CVE-2026-30943

MEDIUM

Gokapi <2.2.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.

Scores

CVSS v3 4.1
EPSS 0.0001
EPSS Percentile 1.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
forceu/gokapi < 2.2.4
forceu/gokapi 0 - 2.2.4Go
Forceu/Gokapi < 2.2.4
Published Mar 13, 2026
Tracked Since Mar 14, 2026