CVE-2026-29061Disclosure(forceu / gokapi)

LOWCVSS 5.4 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user rank demotion logic allows a demoted user's existing API keys to retain ApiPermManageFileRequests and ApiPermManageLogs permissions, enabling continued access to upload-request management and log viewing endpoints after the user has been stripped of all privileges. This issue has been patched in version 2.2.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gokapi

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
gokapi

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-06: 4Technical Details · 2026-03-06: 403-06
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-29061 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user… https://www.cve.org/CVERecord?id=CVE-2026-29061

    Post summary

    The excerpt announces a privilege escalation vulnerability in Gokapi (prior to version 2.2.3) and links to the CVE record, but offers no PoC, exploit, active exploitation, or patch details.

    10000184
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-29061 Gokapi Privilege Escalation Vulnerability in User Rank Demotion Logic Before 2.2.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29061

    Post summary

    The post announces CVE‑2026‑29061, describing a privilege escalation flaw in Gokapi’s user rank demotion logic before version 2.2.3, and links to a vulnerability database entry without providing PoC, exploit, or patch details.

    1000042
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29061 - Gokapi: Privilege escalation via incomplete API-key permission revocation on user rank demotion Intel Report: https://ift.tt/YkdrxMp

    Post summary

    The alert announces CVE‑2026‑29061 as a privilege‑escalation vulnerability caused by incomplete API‑key revocation during user rank demotion, but no PoC, exploit, or patch information is supplied.

    1000044
    343 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29061 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user… https://www.cve.org/CVERecord?id=CVE-2026-29061 ----- Traducción: CVE-2026-29061 Gok… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-29061, describing a privilege escalation bug in Gokapi versions prior to 2.2.3, and links to the official CVE record.

    0000030
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appforceugokapi---

Explore more