Insecure Direct Object Reference in Gophish by Gophish
CVE-2026-107270

7.1HIGH

Key Information:

Vendor

Gophish

Status
Vendor
CVE Published:
7 October 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-107270?

Gophish version 0.12.1 is susceptible to an insecure direct object reference (IDOR) vulnerability that can be exploited by authenticated users. This flaw permits attackers to manipulate POST requests to key API endpoints such as /api/groups/, /api/templates/, /api/pages/, and /api/smtp/. By supplying a sequential user ID, an attacker can replace and reassign resources such as groups, templates, and pages, thereby locking out legitimate owners and compromising sensitive recipient lists. This vulnerability poses a serious risk to user account security and data integrity, enabling unauthorized access and potential data leakage.

Affected Version(s)

gophish 0 <= 0.12.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sohaib Harraoui (Ostorlab)
.