Gao · Electronic Protest Docketing System · CVE-2026-54105
**Name of the Vulnerable Software and Affected Versions**
U.S. GAO Electronic Protest Docketing System (EPDS) (affected versions not specified)
U.S. CBCA Electronic Docketing System (EDS) (affected versions not specified)
**Description**
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information. A remote, unauthenticated attacker can submit a request to the 'update-profile/' API endpoint using an arbitrary `user id` parameter to receive a JSON response containing account-specific details, such as the associated email address.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.