cvedb.io
CVE-2026-30943
MEDIUM · CVSS 4.1
EPSS exploitation probability: 0%
Published 2026-03-13T19:54:35.573 · Last modified 2026-06-17T10:33:11.800

Summary

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the deleteNewFile flag, bypassing the requirement for UserPermDeleteOtherUploads. This vulnerability is fixed in 2.2.4.

Affected products

forceu — gokapi

Does this affect you?

Add your gear to cvedb and we'll alert you only when forceu ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.