CVE-2026-56309: Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint
Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist outside normal bundle metadata, and survive app deletion, enabling storage and bandwidth abuse.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56309?
The severity of CVE-2026-56309 is medium with a score of 5.3.
How do I fix CVE-2026-56309?
To fix CVE-2026-56309, ensure that plan and quota restrictions are enforced on the /files/upload/attachments endpoint.
What are the potential impacts of CVE-2026-56309?
CVE-2026-56309 can allow attackers to upload arbitrary attachments and create publicly readable R2 objects, bypassing plan restrictions.
Who is affected by CVE-2026-56309?
CVE-2026-56309 affects users of Capgo versions before 12.128.2.
What type of vulnerability is CVE-2026-56309?
CVE-2026-56309 is a bypass vulnerability related to unrestricted attachment uploads.