CVE-2026-82269
moderateAccount Lockout Bypass via API Authentication in Gophish Through 0.12.1
Gophish through 0.12.1, an open-source phishing simulation framework, fails to enforce account lockout and mandatory password-change policies in its API authentication middleware (CWE-288). An attacker or compromised client holding a valid API key can continue calling the API even after an administrator has locked the account or flagged it for a password change. This lets the attacker retain full API access, meaning they can create and launch phishing campaigns, modify sending profiles, templates and landing pages, and read campaign results such as recipient lists, email opens, submissions and captured credentials, which undermines containment during incident response. Any organization running Gophish 0.12.1 or earlier that relies on account lockout or forced password changes to cut off API-driven accounts is affected; the flaw requires a valid API key, so it is a policy-enforcement gap rather than an unauthenticated bypass. There is no known exploitation, no public proof-of-concept, and the issue is not in CISA KEV, with EPSS estimating roughly a 0.3% chance of exploitation in the next 30 days.
What to do: Until a patched release is published (check the Gophish GitHub releases), do not rely on account lockout or forced password changes to sever API access; instead revoke or regenerate the affected user's API key when locking or resetting an account. Audit API activity for unexpected campaign creation, template edits or email sends, and restrict API access to trusted management networks where possible.
| gophish (open-source project) Gophish | all versions through and including 0.12.1 (no fixed release identified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
- Weakness
- CWE-288
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.