<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:32:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330047</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330047</link>
      <description>EUVD-2026-330047</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330047</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54105</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54105</link>
      <description>&lt;p&gt;The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the &amp;#39;update-profile/&amp;#39; API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary &amp;#39;user_id&amp;#39; parameter and receive a JSON response containing account-specific information, including the associated email address.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the &amp;#39;update-profile/&amp;#39; API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary &amp;#39;user_id&amp;#39; parameter and receive a JSON response containing account-specific information, including the associated email address.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54105</guid>
    </item>
    <item>
      <title>GHSA-79rr-2p25-73c5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-79rr-2p25-73c5</link>
      <description>&lt;p&gt;The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the &amp;#39;update-profile/&amp;#39; API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary &amp;#39;user_id&amp;#39; parameter and receive a JSON response containing account-specific information, including the associated email address.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the &amp;#39;update-profile/&amp;#39; API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary &amp;#39;user_id&amp;#39; parameter and receive a JSON response containing account-specific information, including the associated email address.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-79rr-2p25-73c5</guid>
    </item>
    <item>
      <title>VA-26-169-01 — U.S. GAO EPDS and CBCA EDS multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/va-26-169-01</link>
      <description>&lt;p&gt;The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the &amp;#39;/update-profile/N&amp;#39; API endpoint. A remote, unauthenticated attacker could change an arbitrary user&amp;#39;s password. The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the &amp;#39;epds_role_id&amp;#39; parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges. The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the &amp;#39;update-profile/&amp;#39; API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary &amp;#39;user_id&amp;#39; parameter and receive a JSON response containing account-specific information, including the associated email address. The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the &amp;#39;/update-profile/N&amp;#39; API endpoint. A remote, unauthenticated attacker could change an arbitrary user&amp;#39;s password. The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the &amp;#39;epds_role_id&amp;#39; parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges. The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the &amp;#39;update-profile/&amp;#39; API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary &amp;#39;user_id&amp;#39; parameter and receive a JSON response containing account-specific information, including the associated email address. The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/va-26-169-01</guid>
    </item>
  </channel>
</rss>
