csaf_cisa_it:va-26-169-01

CRITICAL CVSS 9.8 csaf_cisa_it
Description

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users' passwords and gain administrative privileges.

Timeline
Published
2026-06-18 15:45 UTC
Last Modified
2026-06-18
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).",
        "title": "Legal Notice"
      },
      {
        "category": "other",
        "text": "Worldwide",
        "title": "Countries and Areas Deployed"
      },
      {
        "category": "other",
        "text": "Information Technology",
        "title": "Critical Infrastructure Sectors"
      },
      {
        "category": "summary",
        "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users' passwords and gain administrative privileges.",
        "title": "Risk Evaluation"
      },
      {
        "category": "general",
        "text": "These vulnerabilities were confirmed to be fixed as of 2026-03-19.",
        "title": "Recommended Practices"
      },
      {
        "category": "other",
        "text": "United States",
        "title": "Company Headquarters Location"
      }
    ],
    "publisher": {
      "category": "coordinator",
      "contact_details": "https://www.cisa.gov/report",
      "issuing_authority": "CISA",
      "name": "CISA",
      "namespace": "https://www.cisa.gov/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Vulnerability Advisory VA-26-169-01 CSAF",
        "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
      }
    ],
    "title": "U.S. GAO EPDS and CBCA EDS multiple vulnerabilities",
    "tracking": {
      "current_release_date": "2026-06-18T15:45:16Z",
      "generator": {
        "engine": {
          "name": "VINCE-NT",
          "version": "1.15.0+build.89"
        }
      },
      "id": "VA-26-169-01",
      "initial_release_date": "2026-06-18T15:45:16Z",
      "revision_history": [
        {
          "date": "2026-06-18T15:45:16Z",
          "number": "1.0.0",
          "summary": "Initial publication"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22",
                  "product_id": "CSAFPID-0001"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0002"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22",
                  "product_id": "CSAFPID-0003"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0004"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22",
                  "product_id": "CSAFPID-0005"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0006"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22",
                  "product_id": "CSAFPID-0007"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0008"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          }
        ],
        "category": "vendor",
        "name": "Government Accountability Office"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19",
                  "product_id": "CSAFPID-0009"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0010"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19",
                  "product_id": "CSAFPID-0011"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0012"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19",
                  "product_id": "CSAFPID-0013"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0014"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19",
                  "product_id": "CSAFPID-0015"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0016"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          }
        ],
        "category": "vendor",
        "name": "Civilian Board of Contract Appeals"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54103",
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:N/A:Y/T:T/2026-06-11T16:17:36Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54103"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS unauthenticated password change"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54104",
      "cwe": {
        "id": "CWE-602",
        "name": "Client-Side Enforcement of Server-Side Security"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:N/A:N/T:T/2026-06-11T16:16:59Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54104"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        },
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS client-based privilege escalation"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54105",
      "cwe": {
        "id": "CWE-639",
        "name": "Authorization Bypass Through User-Controlled Key"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary 'user_id' parameter and receive a JSON response containing account-specific information, including the associated email address.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:N/A:Y/T:P/2026-06-11T16:16:19Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54105"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS user information disclosure"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54106",
      "cwe": {
        "id": "CWE-940",
        "name": "Improper Verification of Source of a Communication Channel"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:P/A:N/T:P/2026-06-11T19:54:32Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54106"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS network access control bypass"
    }
  ]
}
View JSON API Download JSON