CVE-2026-56314: Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing appversions.deleted filter in channel version joins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56314?
CVE-2026-56314 has a severity rating of high, with a score of 7.1.
What is CVE-2026-56314 about?
CVE-2026-56314 involves a missing deletion filter in the /updates endpoint of Capgo, allowing deleted app versions to remain selectable.
Who is affected by CVE-2026-56314?
Users of Capgo prior to version 12.128.12 are affected by CVE-2026-56314.
How do I fix CVE-2026-56314?
To mitigate CVE-2026-56314, upgrade to Capgo version 12.128.12 or later.
What can attackers do with CVE-2026-56314?
Attackers can exploit CVE-2026-56314 to deploy deleted bundles to devices due to the lack of filtering.