CVE-2026-82269 HIGH

CVE-2026-82269: Gophish Account Lockout and Forced Password Change Bypassable via API Key

Vendor Gophish
Product gophish
Weakness CWE-288
Published August 28, 2026
Last update August 28, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 28, 2026 Record updated

Related vulnerabilities

04Related CVE