CVE-2026-107270

high

Description

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.

References

https://www.vulncheck.com/advisories/gophish-through-0.12.1-object-takeover-via-client-supplied-id-on-api-create-endpoints

https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/models/group.go#L194-L200

https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/group.go#L28-L43

https://github.com/gophish/gophish

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94401

https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html

Details

Source: Mitre, NVD

Published: 2026-10-07

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:C/A:N

Severity: High

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Severity: High

CVSS v4

Base Score: 7.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00199