Insecure Direct Object Reference in Gophish by Gophish
CVE-2026-107270
Key Information:
Badges
What is CVE-2026-107270?
Gophish version 0.12.1 is susceptible to an insecure direct object reference (IDOR) vulnerability that can be exploited by authenticated users. This flaw permits attackers to manipulate POST requests to key API endpoints such as /api/groups/, /api/templates/, /api/pages/, and /api/smtp/. By supplying a sequential user ID, an attacker can replace and reassign resources such as groups, templates, and pages, thereby locking out legitimate owners and compromising sensitive recipient lists. This vulnerability poses a serious risk to user account security and data integrity, enabling unauthorized access and potential data leakage.
Affected Version(s)
gophish 0 <= 0.12.1
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
