CVE-2026-29060Disclosure(forceu / gokapi)

LOWCVSS 5.0 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so. The user must be registered with Gokapi. If there are no users with access to the admin/upload menu, there is no impact. This issue has been patched in version 2.2.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gokapi

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
gokapi

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-06: 4Technical Details · 2026-03-06: 203-06
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets5 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-29060 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create o… https://www.cve.org/CVERecord?id=CVE-2026-29060

    Post summary

    The text announces CVE‑2026‑29060 for Gokapi versions prior to 2.2.3, noting that a registered user without privileges can exploit an unspecified flaw, but it provides no PoC, active exploitation evidence or patch information.

    00010190
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29060 Privilege Escalation in Gokapi File Sharing Server Before Version... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29060 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new privilege‑escalation vulnerability (CVE-2026-29060) affecting the Gokapi File Sharing Server has been announced, but no PoC, exploit code, active exploitation data, or patch information is provided.

    1000045
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29060 - Gokapi: Privilege escalation with auth token Intel Report: https://ift.tt/VFaEnB9

    Post summary

    The alert reports CVE‑2026‑29060, a privilege‑escalation flaw in Gokapi involving auth tokens, but provides no evidence of exploitation, PoC, or available mitigations.

    1000047
    343 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-29060 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create o… https://www.cve.org/CVERecord?id=CVE-2026-29060 ----- Traducción: CVE-2026-29060 Gok… http://infoflow.cloud`

    Post summary

    The post cites CVE‑2026‑29060 with a link to its CVE record but provides no additional technical, exploit, or mitigation details.

    0000026
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appforceugokapi---

Explore more