Junglewise Threat Intelligence

CVE-2026-56309: Capgo plan bypass via unrestricted attachment upload endpoint

CVE-2026-56309 · Severity: medium · CVSS 5.4 · Published 2026-07-10

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing mobile app updates, failed to properly enforce subscription plan limits on its file upload system. This allowed users with blocked or restricted accounts to continue uploading files and consuming storage and bandwidth without paying. These unauthorized files remained publicly accessible and persisted even after the associated application was deleted, leading to potential resource abuse and unexpected costs for the service provider.

Technical details

A vulnerability in Capgo's backend allows apps that are otherwise blocked due to plan or quota restrictions to bypass these gates via the /files/upload/attachments endpoint. While the /updates endpoint correctly enforces plan status, the attachment upload route only checks for a valid upload-scoped API key and basic write access, failing to verify the account's subscription standing. Attackers can use this to upload arbitrary files to R2 storage that are not tracked in standard application metadata (app_versions). Furthermore, these objects are not purged during the standard app deletion process, leading to orphaned data and persistent resource exhaustion. The issue was addressed in version 12.128.2 by implementing plan enforcement on the affected routes.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-07-10: disclosed: NVD publication date

References

Related threats