The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
History

Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Civilian Board Of Contract Appeals
Civilian Board Of Contract Appeals electronic Docketing System (eds)
Government Accountability Office
Government Accountability Office electronic Protest Docketing System (epds)
Vendors & Products Civilian Board Of Contract Appeals
Civilian Board Of Contract Appeals electronic Docketing System (eds)
Government Accountability Office
Government Accountability Office electronic Protest Docketing System (epds)

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
Title U.S. GAO EPDS and CBCA EDS unauthenticated password change
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published: 2026-06-18T16:12:35.433Z

Updated: 2026-06-19T03:55:58.779Z

Reserved: 2026-06-11T19:41:26.775Z

Link: CVE-2026-54103

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.