CVE-2026-53867: Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53867?
The severity of CVE-2026-53867 is rated as medium with a score of 5.3.
How do I fix CVE-2026-53867?
To fix CVE-2026-53867, update Capgo to version 12.128.2 or higher to ensure proper management of profile images.
What is the risk associated with CVE-2026-53867?
CVE-2026-53867 presents a risk due to unauthorized access to previously uploaded profile images via orphaned URLs.
Who is affected by CVE-2026-53867?
Users of Capgo versions prior to 12.128.2 are affected by CVE-2026-53867.
What type of vulnerability is CVE-2026-53867?
CVE-2026-53867 is a vulnerability related to orphaned file retention, specifically concerning profile image replacement.