HIGHVulnerability

CVE-2026-82269

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

Properties

severity
HIGH
score
8.1
cve_id
CVE-2026-82269
signal_observed_at
2026-09-23T22:44:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-28T20:20:17.650
last_modified
2026-09-23T17:17:43.640

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass Using an Alternate Path or Channel

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82269 — Ninja Signal Threat Intelligence | Ninja Signal