CVE-2026-28682 is a medium-severity vulnerability affecting Gokapi, a self-hosted file sharing server, specifically versions prior to 2.2.3. The flaw lies in the /uploadStatus SSE implementation, which inadvertently broadcasts global upload states, including file_id values, to any authenticated user, regardless of their ownership of the files. This allows an authenticated attacker (PR:L) to potentially gain unauthorized access to sensitive information (C:L) and modify data (I:L) by observing file IDs not scoped to their account, with low attack complexity (AC:L) and no user interaction required (UI:N). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.3CPE matchmatch criteria | cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.