CVE-2026-107270: IDOR Vulnerability in Gophish API
Gophish versions 0.12.1 and earlier are vulnerable to an Insecure Direct Object Reference (IDOR) flaw allowing authenticated users to modify or hijack unauthorized administrative objects.
CVE search metadata
CVE search record: CVE-2026-107270. Severity: high. CVSS: 7.1. KEV: no. Product: Gophish (<= 0.12.1). Brief: CVE-2026-107270: IDOR Vulnerability in Gophish API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gophish-idor/
Gophish versions 0.12.1 and earlier contain an insecure direct object reference (IDOR) vulnerability that allows an authenticated user to perform unauthorized modifications to critical system objects. By manipulating the sequential ID parameter within POST requests directed at specific API endpoints, an attacker can overwrite or reassign existing groups, email templates, landing pages, and SMTP sending profiles. This vulnerability effectively allows an attacker to lock out legitimate users from their configuration assets and potentially expose sensitive recipient lists associated with those campaigns. Because Gophish is frequently used for internal phishing simulations, the impact of this vulnerability includes potential cross-departmental data leakage and the compromise of simulated phishing campaign integrity. Organizations using self-hosted Gophish instances are advised to restrict access to the API and monitor for suspicious administrative object modifications until a patched version is available.
Impact
The vulnerability allows for the unauthorized takeover of administrative objects, leading to the lockout of legitimate users and the exposure of sensitive recipient data. Successful exploitation permits an attacker to alter the configuration of ongoing simulations or use another user's SMTP profiles to send malicious email, undermining the platform's security controls.
Recommendation
- Monitor web server access logs for anomalous POST requests to API paths (/api/groups/, /api/templates/, /api/pages/, /api/smtp/) that reference ID parameters inconsistent with the authenticated user session.
- Limit access to the Gophish web interface and API to trusted administrative subnets via firewall rules.
- Audit existing Gophish configurations for unauthorized changes to SMTP profiles or unexpected user associations.
- Patch Gophish as soon as the vendor releases a version addressing CVE-2026-107270.
Immediate actions
Deploy web application firewall rules or access control lists to restrict access to /api/ endpoints in Gophish
Threat Hunt
Search web logs for POST requests to /api/ paths with sequential integer IDs
Data: Web access logs (cs-method, cs-uri-stem)
Enrichment needed
- Monitor for upstream patches from the Gophish repository (CTI) No fixed version is currently listed
Mitigations
Upgrade Gophish once a version > 0.12.1 is released
CVE-2026-107270
Detection coverage 1
Detect CVE-2026-107270 Exploitation - API Object Modification
highDetects potential IDOR exploitation via POST requests to Gophish API endpoints used for object management.
Detection queries are available on the platform. Get full rules →