Unrated severityNVD Advisory· Published Jun 29, 2026· Updated Jul 1, 2026
Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API
CVE-2026-56780
Description
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/modoboa/modoboa/commit/a1878c4920a6e47c3217c6ff1ed4a8753c202661mitrepatch
- www.vulncheck.com/advisories/modoboa-insecure-direct-object-reference-in-account-password-change-apimitrethird-party-advisory
- github.com/modoboa/modoboa/pull/4038mitreissue-tracking
News mentions
0No linked articles in our index yet.