CVE-2026-107269
Deferred Deferred - Pending Action

Timing Attack in Gophish Admin Login

Vulnerability report for CVE-2026-107269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gophish gophish 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Gophish through version 0.12.1 has a timing discrepancy vulnerability in the AdminServer.Login function. This flaw allows unauthenticated attackers to check if a username exists by measuring how long the system takes to respond to login attempts. The system uses bcrypt for password hashing, which takes longer for valid usernames, enabling attackers to distinguish between existing and non-existing accounts.

Detection Guidance

To detect this vulnerability, monitor login response times for POST requests to /login in Gophish. Existing accounts will show delayed bcrypt comparisons compared to non-existent ones. Use tools like curl to send test requests and measure response times for different usernames.

Impact Analysis

This vulnerability can allow attackers to identify valid usernames in your system, which they can then use for further attacks like password guessing or credential stuffing. If you use Gophish for phishing simulations or email campaigns, attackers could exploit this to target specific users within your organization.

Compliance Impact

The vulnerability allows unauthenticated attackers to enumerate valid usernames by measuring login response times, which could lead to credential stuffing attacks. This may violate GDPR's data protection principles requiring appropriate security measures to prevent unauthorized access to personal data, and HIPAA's safeguards for protecting electronic protected health information (ePHI) by enabling unauthorized access to user accounts.

Mitigation Strategies

Upgrade Gophish to a version beyond 0.12.1 where this issue is fixed. If upgrading is not possible, implement rate limiting on the /login endpoint and disable timing-based username enumeration by modifying the login logic to return consistent response times.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107269. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart