Skip to content
Threat Feed
high advisory

CVE-2026-107270: IDOR Vulnerability in Gophish API

Gophish versions 0.12.1 and earlier are vulnerable to an Insecure Direct Object Reference (IDOR) flaw allowing authenticated users to modify or hijack unauthorized administrative objects.

CVE search metadata

CVE search record: CVE-2026-107270. Severity: high. CVSS: 7.1. KEV: no. Product: Gophish (<= 0.12.1). Brief: CVE-2026-107270: IDOR Vulnerability in Gophish API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gophish-idor/

Gophish versions 0.12.1 and earlier contain an insecure direct object reference (IDOR) vulnerability that allows an authenticated user to perform unauthorized modifications to critical system objects. By manipulating the sequential ID parameter within POST requests directed at specific API endpoints, an attacker can overwrite or reassign existing groups, email templates, landing pages, and SMTP sending profiles. This vulnerability effectively allows an attacker to lock out legitimate users from their configuration assets and potentially expose sensitive recipient lists associated with those campaigns. Because Gophish is frequently used for internal phishing simulations, the impact of this vulnerability includes potential cross-departmental data leakage and the compromise of simulated phishing campaign integrity. Organizations using self-hosted Gophish instances are advised to restrict access to the API and monitor for suspicious administrative object modifications until a patched version is available.

Impact

The vulnerability allows for the unauthorized takeover of administrative objects, leading to the lockout of legitimate users and the exposure of sensitive recipient data. Successful exploitation permits an attacker to alter the configuration of ongoing simulations or use another user's SMTP profiles to send malicious email, undermining the platform's security controls.

Recommendation

  • Monitor web server access logs for anomalous POST requests to API paths (/api/groups/, /api/templates/, /api/pages/, /api/smtp/) that reference ID parameters inconsistent with the authenticated user session.
  • Limit access to the Gophish web interface and API to trusted administrative subnets via firewall rules.
  • Audit existing Gophish configurations for unauthorized changes to SMTP profiles or unexpected user associations.
  • Patch Gophish as soon as the vendor releases a version addressing CVE-2026-107270.

Immediate actions

Deploy web application firewall rules or access control lists to restrict access to /api/ endpoints in Gophish

IT Operations 24h

Threat Hunt

Search web logs for POST requests to /api/ paths with sequential integer IDs

T1068 high medium confidence hunt now

Data: Web access logs (cs-method, cs-uri-stem)

Enrichment needed

  • Monitor for upstream patches from the Gophish repository (CTI) No fixed version is currently listed

Mitigations

Upgrade Gophish once a version > 0.12.1 is released

medium_term IT Operations

CVE-2026-107270

Detection coverage 1

Detect CVE-2026-107270 Exploitation - API Object Modification

high

Detects potential IDOR exploitation via POST requests to Gophish API endpoints used for object management.

sigma tactics: privilege_escalation techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →