Account Lockout and Password Change Bypass in Gophish by Gophish
CVE-2026-82269

8.6HIGH

Key Information:

Vendor

Gophish

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82269?

The Gophish product version 0.12.1 contains a vulnerability that permits attackers to bypass essential security mechanisms, specifically account lockout and required password changes. This occurs due to insufficient enforcement in the API authentication middleware, allowing users with valid API keys to maintain their access even when their accounts should be restricted. This flaw creates an alarming security risk, as it undermines the effectiveness of account management controls designed to protect against unauthorized access.

Affected Version(s)

gophish 0 <= 0.12.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.