CyberSec.Space Logo
Back to CVE Browser

CVE-2026-53867

MEDIUM
4.3
CVSS Severity Score
EPSS Score0.1410%
EPSS Percentile7.97th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities