The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
References
Configurations
No configuration.
History
19 Jun 2026, 06:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 17:16
Updated : 2026-06-22 14:17
NVD link : CVE-2026-54103
Mitre link : CVE-2026-54103
CVE.ORG link : CVE-2026-54103
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
