CVE-2026-56314
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
22/06/2026
Last modified:
23/06/2026
Description
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
7.10
Severity 3.x
HIGH



