CVE-2026-56314

Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-22 22:16

Updated : 2026-06-23 15:16


NVD link : CVE-2026-56314

Mitre link : CVE-2026-56314

CVE.ORG link : CVE-2026-56314


JSON object : View

Products Affected

No product.

CWE
CWE-672

Operation on a Resource after Expiration or Release