PT-2026-83292 · Gophish · Gophish

·

CVE-2026-82269

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gophish versions prior to 0.12.2
Description The API authentication middleware fails to enforce account lockout and password change requirements. This allows attackers possessing valid API keys to bypass these security controls, maintaining full API access even if the associated account is locked or requires a password change.
Recommendations Update Gophish to version 0.12.2 or later.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82269

Affected Products

Gophish