CVE-2026-107270: high-severity vulnerability in gophish
Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints
Published
38Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.1
exploitation probability
—
observed exploitation
nono source reports it
1 public exploit(s)
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
gophish · gophishpublic PoCs found — 1
cve_referenceblog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — gophish
In the same product, most dangerous first.
CVE-2026-39904HIGHGophish 0.12.1 Denial of Service via Office Document UploadEPSS 0.4%CVE-2026-82269HIGHGophish Account Lockout and Forced Password Change Bypassable via API KeyEPSS 0.4%CVE-2026-107273MEDIUMGophish 0.11.0 through 0.12.1 SSRF via POST /api/import/siteEPSS —CVE-2026-107272LOWGophish through 0.12.1 XSS via Unescaped SMTP Server Error MessagesEPSS —CVE-2026-107271MEDIUMGophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For SpoofingEPSS —CVE-2026-107269MEDIUMGophish through 0.12.1 Username Enumeration via POST /login Timing DiscrepancyEPSS —
References
https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.htmlhttps://github.com/gophish/gophishhttps://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/group.go#L28-L43https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/models/group.go#L194-L200https://www.vulncheck.com/advisories/gophish-through-0.12.1-object-takeover-via-client-supplied-id-on-api-create-endpoints