CVE-2026-56314
Capgo
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.
- CVSS
- 7.1
- EPSS
- 0.30% 22.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23