CVE-2026-82269
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gophish | gophish | 0 <= 0.12.1 | affected |
Weaknesses
- CWE-288: Authentication Bypass Using an Alternate Path or Channel
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
- https://github.com/gophish/gophish/issues/9440
- https://github.com/gophish/gophish
- https://github.com/gophish/gophish/blob/95618469799295e2c0fec980805a2dfbb818816b/middleware/middleware.go
- https://www.vulncheck.com/advisories/gophish-account-lockout-and-forced-password-change-bypassable-via-api-key
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.