CVE-2026-54104
Awaiting Analysis Awaiting Analysis - Queue
Privilege Escalation in GAO EPDS and CBCA EDS Systems

Publication date: 2026-06-18

Last updated on: 2026-06-18

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-18
Last Modified
2026-06-18
Generated
2026-06-19
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and the Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS). It occurs because these systems trust client-provided values for the 'epds_role_id' parameter without verifying them. This flaw allows a remote, authenticated attacker to escalate their own privileges by manipulating this parameter.

Impact Analysis

The vulnerability can allow an attacker who is already authenticated to increase their privileges within the affected systems. This means the attacker could gain unauthorized access to higher-level functions or sensitive information, potentially leading to data breaches, unauthorized actions, or disruption of services.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54104. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart