CVE-2026-107270highCWE-639

CVE-2026-107270: high-severity vulnerability in gophish

Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints

Published

38Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.1
exploitation probability
—
observed exploitation
nono source reports it
1 public exploit(s)
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
gophish · gophish
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.