CVE-2026-107270 PUBLISHED

Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints

Assigner: VulnCheck
Reserved: 07.10.2026 Published: 07.10.2026 Updated: 07.10.2026

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor gophish
Product gophish
Versions Default: unaffected
  • affected from 0 to 0.12.1 (incl.)

Credits

  • Sohaib Harraoui (Ostorlab) finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE