云虫漏洞库

CVE-2026-82269 - Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required. - 漏洞详情

漏洞编号:CVE-2026-82269

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-82269

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-288

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

相关链接

相关漏洞

« 返回首页