Account Lockout and Password Change Bypass in Gophish by Gophish
CVE-2026-82269
8.6HIGH
What is CVE-2026-82269?
The Gophish product version 0.12.1 contains a vulnerability that permits attackers to bypass essential security mechanisms, specifically account lockout and required password changes. This occurs due to insufficient enforcement in the API authentication middleware, allowing users with valid API keys to maintain their access even when their accounts should be restricted. This flaw creates an alarming security risk, as it undermines the effectiveness of account management controls designed to protect against unauthorized access.
Affected Version(s)
gophish 0 <= 0.12.1
