CVE-2026-30943

MEDIUM

Gokapi < 2.2.4 - Incorrect Authorization via File Replace API

Title source: llm
STIX 2.1

Description

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.

References (2)

Core 2
Core References

Scores

CVSS v3 4.1
EPSS 0.0018
EPSS Percentile 7.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
forceu/gokapi < 2.2.4
forceu/gokapi 0 - 2.2.4Go
Forceu/Gokapi < 2.2.4
Published Mar 13, 2026
Tracked Since Mar 14, 2026