High severity7.1NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-107270
CVE-2026-107270
Description
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.
Affected products
1Patches
Vulnerability mechanics
References
4- blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.htmlnvd
- github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/group.gonvd
- github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/models/group.gonvd
- www.vulncheck.com/advisories/gophish-through-0.12.1-object-takeover-via-client-supplied-id-on-api-create-endpointsnvd
News mentions
0No linked articles in our index yet.