CVE-2026-82269
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.30%
- CWE
- CWE-288
- Published
- 2026-08-28
- Last modified
- 2026-08-28
Affected products
- gophish gophish
Weakness type
Related vulnerabilities
- CVE-2026-86084 — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
- CVE-2026-83527 — An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a...
- CVE-2026-62650 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side...
- CVE-2026-76169 — fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
- CVE-2026-62916 — Microsoft Entra ID Elevation of Privilege Vulnerability
- CVE-2026-84777 — WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability
- CVE-2026-16647 — Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
- CVE-2026-81168 — CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105