{"id":"CVE-2026-53867","title":"Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement","summary":"Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cvssSource":"cna","cwe":["CWE-459"],"vendor":"Capgo","product":"Capgo","affected":["Capgo < 12.128.2"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-15T16:52:41.414750Z"},"published":"2026-06-12","updated":"2026-09-24","sourceUpdated":"2026-09-24T14:17:47.950Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-53867","references":[{"url":"https://github.com/Cap-go/capgo/security/advisories/GHSA-8p92-wcp2-c9j4","label":"GHSA Advisory GHSA-8p92-wcp2-c9j4"},{"url":"https://www.vulncheck.com/advisories/capgo-orphaned-file-retention-via-profile-image-replacement","label":"VulnCheck Advisory: Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement"}],"tags":["cve.org"],"epss":0.00183,"epssPercentile":0.08155,"ingestedAt":"2026-09-24T15:45:56.728Z","slug":"CVE-2026-53867","body":"## Overview\n\nCapgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.\n\n## Affected\n\n- `Capgo < 12.128.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}