PT-2026-83292 · Gophish · Gophish
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Gophish versions prior to 0.12.2
Description
The API authentication middleware fails to enforce account lockout and password change requirements. This allows attackers possessing valid API keys to bypass these security controls, maintaining full API access even if the associated account is locked or requires a password change.
Recommendations
Update Gophish to version 0.12.2 or later.
Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gophish