Timing Discrepancy Vulnerability in Gophish by Gophish Inc.
CVE-2026-107269

6.3MEDIUM

Key Information:

Vendor

Gophish

Status
Vendor
CVE Published:
7 October 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-107269?

Gophish version 0.12.1 is susceptible to a timing discrepancy vulnerability in the AdminServer.Login component. This security flaw enables unauthenticated attackers to exploit the response time discrepancies during the login process to enumerate valid usernames. By submitting various candidate usernames via the POST request to /login, attackers can detect delays caused by the bcrypt comparison for existing accounts, thereby honing in on potential targets for subsequent password guessing or credential stuffing attacks. It is crucial for users managing Gophish to implement mitigations and ensure their systems remain secure against such enumeration tactics.

Affected Version(s)

gophish 0 <= 0.12.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sohaib Harraoui (Ostorlab)
.