CVE-2026-53867 - Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
CVE ID :CVE-2026-53867
Published : June 12, 2026, 10:16 p.m. | 3 hours, 32 minutes ago
Description :Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 12, 2026, 10:16 p.m. | 3 hours, 32 minutes ago
Description :Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...