{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agophishgophish/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gophish:gophish:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-82269"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gophish (\u003c= 0.12.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","api-security"],"_cs_type":"advisory","_cs_vendors":["Gophish"],"content_html":"\u003cp\u003eGophish versions through 0.12.1 contain a critical security flaw (CVE-2026-82269) within the application's API authentication middleware. The implementation fails to correctly enforce account security policies, specifically account lockout states and mandatory password rotation requirements, when authentication is performed via the API. This vulnerability allows an attacker who has acquired a valid API key to bypass these security constraints. Even if an administrator disables an account or mandates a password reset for compromised credentials, the API middleware continues to honor existing, valid API keys. This enables persistent access to sensitive data and Gophish operational controls despite intended account restrictions. Defenders should identify all active API keys in their environment and verify them against the status of the associated user accounts until the software can be patched to a version that properly integrates state checks into the API authentication logic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized persistence and potential privilege escalation within a Gophish deployment. By bypassing lockout and password change requirements, an attacker can maintain long-term access to phishing campaign configurations, sensitive target data, and administrative API endpoints. This significantly lowers the barrier for attackers to maintain access after a primary credential compromise has been detected and mitigated by an administrator.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an audit of all active Gophish API keys and cross-reference them with currently active and compliant user accounts.\u003c/li\u003e\n\u003cli\u003eReview Gophish API access logs to identify anomalous or unauthorized persistent connections.\u003c/li\u003e\n\u003cli\u003eUpgrade Gophish to a version beyond 0.12.1 once the vendor provides a patch addressing CVE-2026-82269.\u003c/li\u003e\n\u003cli\u003eImplement restrictive network access control lists (ACLs) to limit access to Gophish API endpoints to known, trusted management IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:38:07Z","date_published":"2026-08-28T21:38:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gophish-api-bypass/","summary":"Gophish versions through 0.12.1 contain a vulnerability in the API authentication middleware that fails to enforce account lockout and password change requirements, allowing attackers with valid API keys to maintain persistent unauthorized access.","title":"Gophish API Authentication Middleware Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-gophish-api-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gophish:gophish:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}