PT-2026-53657 · Modoboa · Modoboa

·

CVE-2026-56780

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Modoboa versions prior to 2.9.0
Description An insecure direct object reference (IDOR) occurs in the 'PUT /api/v1/accounts/{pk}/password/' endpoint. This issue allows domain administrators to bypass object-level access controls by manipulating the {pk} variable to change the password of any user, including superadmins, leading to full account takeover.
Recommendations Update to version 2.9.0 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56780

Affected Products

Modoboa