CVE-2026-54104
U.S. GAO EPDS and CBCA EDS client-based privilege escalation
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Civilian Board of Contract Appeals · Electronic Docketing System (EDS)Government Accountability Office · Electronic Protest Docketing System (EPDS)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →