CVE-2026-54103 PUBLISHED

U.S. GAO EPDS and CBCA EDS unauthenticated password change

Assigner: cisa-cg
Reserved: 11.06.2026 Published: 18.06.2026 Updated: 19.06.2026

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Government Accountability Office
Product Electronic Protest Docketing System (EPDS)
Versions Default: unknown
  • affected from 0 to 2026-02-22 (excl.)
  • Version 2026-02-22 is unaffected
Vendor Civilian Board of Contract Appeals
Product Electronic Docketing System (EDS)
Versions Default: affected
  • affected from 0 to 2026-03-19 (excl.)
  • Version 2026-03-19 is unaffected

Credits

  • Blake Rash, CISA

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE