CVE-2026-29060 Details
Description
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so. The user must be registered with Gokapi. If there are no users with access to the admin/upload menu, there is no impact. This issue has been patched in version 2.2.3.
A privilege escalation vulnerability has been identified in Gokapi, a self-hosted file sharing server, prior to version 2.2.3. The issue allows registered users without the rights to create or modify file requests to generate a short-lived API key that includes those permissions. This vulnerability is only impactful if there are users with access to the admin/upload menu.
Users can update to Gokapi version 2.2.3, which addresses this vulnerability. Instructions for updating can be found in the Gokapi release notes on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Forceu/Gokapi/releases/tag/v2.2.3 | [email protected] | Release Notes |
| https://github.com/Forceu/Gokapi/security/advisories/GHSA-m2hx-wjxc-9fp4 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| forceu gokapi | < 2.2.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | [email protected] |