CVE-2026-107270
Deferred Deferred - Pending Action

Insecure Direct Object Reference in Gophish 0.12.1

Vulnerability report for CVE-2026-107270, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gophish gophish 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Gophish through 0.12.1 has an insecure direct object reference vulnerability. Authenticated users can take over other users' groups, templates, landing pages, and sending profiles by supplying another user's sequential ID in POST requests. This allows attackers to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.

Detection Guidance

To detect this vulnerability, monitor API requests to /api/groups/, /api/templates/, /api/pages/, and /api/smtp/ endpoints for unusual POST requests with sequential IDs. Check for unauthorized modifications to user-owned objects or recipient list exposures. Review logs for repeated failed access attempts or unexpected ownership changes.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive data, such as recipient lists of other users. Attackers could impersonate legitimate users, disrupt operations by locking owners out of their resources, and potentially misuse compromised templates or profiles for phishing campaigns.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR and HIPAA by exposing sensitive recipient data to unauthorized users. It may lead to unauthorized data access, breaches of confidentiality, and failure to maintain data integrity and availability, potentially resulting in legal and financial penalties.

Mitigation Strategies

Immediately upgrade Gophish to a version beyond 0.12.1 to address the insecure direct object reference vulnerability. Review and restrict access to sensitive API endpoints like /api/groups/, /api/templates/, /api/pages/, and /api/smtp/. Monitor for unauthorized changes to user-owned objects and audit user permissions regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107270. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart