CVE-2026-28682Disclosure(forceu / gokapi)

LOWCVSS 6.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and includes file_id values that are not scoped to the requesting user. This issue has been patched in version 2.2.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gokapi

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
gokapi

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-06: 3Technical Details · 2026-03-06: 103-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28682 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadS… https://www.cve.org/CVERecord?id=CVE-2026-28682

    Post summary

    The tweet notes CVE-2026-28682 for Gokapi, indicating an issue with the upload status SSE implementation before version 2.2.3 and linking to the CVE record, but offers no technical, exploit, or remediation details.

    00010210
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28682 Gokapi Authentication Bypass Vulnerability Leaking File Upload Status https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28682

    Post summary

    A new authentication bypass vulnerability (CVE‑2026‑28682) affecting Gokapi has been disclosed, with the flaw leaking file upload status. No exploits, patches, or active exploitation claims are documented.

    1000050
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-28682 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadS… https://www.cve.org/CVERecord?id=CVE-2026-28682 ----- Traducción: CVE-2026-28682 Gok… http://infoflow.cloud`

    Post summary

    The tweet simply references the CVE record link with minimal context, providing no evidence of exploitation, patches, or detailed technical information.

    0000024
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appforceugokapi---

Explore more