Critical severity9.8NVD Advisory· Published Jun 18, 2026· Updated Jun 22, 2026
CVE-2026-54103
CVE-2026-54103
Description
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.