VA-26-169-01
Vulnerability from csaf_cisa - Published: 2026-06-18 15:45 - Updated: 2026-06-18 15:45Summary
U.S. GAO EPDS and CBCA EDS multiple vulnerabilities
Notes
Legal Notice: All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).
Countries and Areas Deployed: Worldwide
Critical Infrastructure Sectors: Information Technology
Risk Evaluation: The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users' passwords and gain administrative privileges.
Recommended Practices: These vulnerabilities were confirmed to be fixed as of 2026-03-19.
Company Headquarters Location: United States
9.8 (Critical)
Affected products
Known affected
2 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22
Government Accountability Office / Electronic Protest Docketing System (EPDS)
|
<2026-02-22 |
Vendor Fix
|
|
|
Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19
Civilian Board of Contract Appeals / Electronic Docketing System (EDS)
|
<2026-03-19 |
Vendor Fix
|
Fixed
2 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22
Government Accountability Office / Electronic Protest Docketing System (EPDS)
|
2026-02-22 |
Vendor Fix
|
|
|
Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19
Civilian Board of Contract Appeals / Electronic Docketing System (EDS)
|
2026-03-19 |
Vendor Fix
|
8.8 (High)
Affected products
Known affected
2 products, the same list as for
CVE-2026-54103
Fixed
2 products, the same list as for
CVE-2026-54103
5.3 (Medium)
Affected products
Known affected
2 products, the same list as for
CVE-2026-54103
Fixed
2 products, the same list as for
CVE-2026-54103
4.7 (Medium)
Affected products
Known affected
2 products, the same list as for
CVE-2026-54103
Fixed
2 products, the same list as for
CVE-2026-54103
References
8 references
| URL | Category |
|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/de… | self |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | external |
| https://www.cve.org/CVERecord?id=CVE-2026-54103 | external |
| https://epds.gao.gov/ | external |
| https://www.eds.cbca.gov/login | external |
| https://www.cve.org/CVERecord?id=CVE-2026-54104 | external |
| https://www.cve.org/CVERecord?id=CVE-2026-54105 | external |
| https://www.cve.org/CVERecord?id=CVE-2026-54106 | external |
{
"document": {
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE"
}
},
"lang": "en-US",
"notes": [
{
"category": "legal_disclaimer",
"text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).",
"title": "Legal Notice"
},
{
"category": "other",
"text": "Worldwide",
"title": "Countries and Areas Deployed"
},
{
"category": "other",
"text": "Information Technology",
"title": "Critical Infrastructure Sectors"
},
{
"category": "summary",
"text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users\u0027 passwords and gain administrative privileges.",
"title": "Risk Evaluation"
},
{
"category": "general",
"text": "These vulnerabilities were confirmed to be fixed as of 2026-03-19.",
"title": "Recommended Practices"
},
{
"category": "other",
"text": "United States",
"title": "Company Headquarters Location"
}
],
"publisher": {
"category": "coordinator",
"contact_details": "https://www.cisa.gov/report",
"issuing_authority": "CISA",
"name": "CISA",
"namespace": "https://www.cisa.gov/"
},
"references": [
{
"category": "self",
"summary": "Vulnerability Advisory VA-26-169-01 CSAF",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
}
],
"title": "U.S. GAO EPDS and CBCA EDS multiple vulnerabilities",
"tracking": {
"current_release_date": "2026-06-18T15:45:16Z",
"generator": {
"engine": {
"name": "VINCE-NT",
"version": "1.15.0+build.89"
}
},
"id": "VA-26-169-01",
"initial_release_date": "2026-06-18T15:45:16Z",
"revision_history": [
{
"date": "2026-06-18T15:45:16Z",
"number": "1.0.0",
"summary": "Initial publication"
}
],
"status": "final",
"version": "1.0.0"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
"product_id": "CSAFPID-0001"
}
},
{
"category": "product_version",
"name": "2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
"product_id": "CSAFPID-0002"
}
}
],
"category": "product_name",
"name": "Electronic Protest Docketing System (EPDS)"
},
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
"product_id": "CSAFPID-0003"
}
},
{
"category": "product_version",
"name": "2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
"product_id": "CSAFPID-0004"
}
}
],
"category": "product_name",
"name": "Electronic Protest Docketing System (EPDS)"
},
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
"product_id": "CSAFPID-0005"
}
},
{
"category": "product_version",
"name": "2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
"product_id": "CSAFPID-0006"
}
}
],
"category": "product_name",
"name": "Electronic Protest Docketing System (EPDS)"
},
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
"product_id": "CSAFPID-0007"
}
},
{
"category": "product_version",
"name": "2026-02-22",
"product": {
"name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
"product_id": "CSAFPID-0008"
}
}
],
"category": "product_name",
"name": "Electronic Protest Docketing System (EPDS)"
}
],
"category": "vendor",
"name": "Government Accountability Office"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
"product_id": "CSAFPID-0009"
}
},
{
"category": "product_version",
"name": "2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
"product_id": "CSAFPID-0010"
}
}
],
"category": "product_name",
"name": "Electronic Docketing System (EDS)"
},
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
"product_id": "CSAFPID-0011"
}
},
{
"category": "product_version",
"name": "2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
"product_id": "CSAFPID-0012"
}
}
],
"category": "product_name",
"name": "Electronic Docketing System (EDS)"
},
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
"product_id": "CSAFPID-0013"
}
},
{
"category": "product_version",
"name": "2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
"product_id": "CSAFPID-0014"
}
}
],
"category": "product_name",
"name": "Electronic Docketing System (EDS)"
},
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
"product_id": "CSAFPID-0015"
}
},
{
"category": "product_version",
"name": "2026-03-19",
"product": {
"name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
"product_id": "CSAFPID-0016"
}
}
],
"category": "product_name",
"name": "Electronic Docketing System (EDS)"
}
],
"category": "vendor",
"name": "Civilian Board of Contract Appeals"
}
]
},
"vulnerabilities": [
{
"acknowledgments": [
{
"names": [
"Blake Rash"
],
"organization": "CISA"
}
],
"cve": "CVE-2026-54103",
"cwe": {
"id": "CWE-306",
"name": "Missing Authentication for Critical Function"
},
"notes": [
{
"category": "summary",
"text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the \u0027/update-profile/N\u0027 API endpoint. A remote, unauthenticated attacker could change an arbitrary user\u0027s password.",
"title": "Description"
},
{
"category": "details",
"text": "SSVCv2/E:N/A:Y/T:T/2026-06-11T16:17:36Z/",
"title": "SSVC"
}
],
"product_status": {
"fixed": [
"CSAFPID-0002",
"CSAFPID-0010"
],
"known_affected": [
"CSAFPID-0001",
"CSAFPID-0009"
]
},
"references": [
{
"category": "external",
"summary": "raw.githubusercontent.com",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
},
{
"category": "external",
"summary": "www.cve.org",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-54103"
},
{
"category": "external",
"summary": "epds.gao.gov",
"url": "https://epds.gao.gov/"
},
{
"category": "external",
"summary": "www.eds.cbca.gov",
"url": "https://www.eds.cbca.gov/login"
}
],
"release_date": "2026-06-18T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0001"
]
},
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0002"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0009"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0010"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"CSAFPID-0001",
"CSAFPID-0009"
]
}
],
"title": "U.S. GAO EPDS and CBCA EDS unauthenticated password change"
},
{
"acknowledgments": [
{
"names": [
"Blake Rash"
],
"organization": "CISA"
}
],
"cve": "CVE-2026-54104",
"cwe": {
"id": "CWE-602",
"name": "Client-Side Enforcement of Server-Side Security"
},
"notes": [
{
"category": "summary",
"text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the \u0027epds_role_id\u0027 parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.",
"title": "Description"
},
{
"category": "details",
"text": "SSVCv2/E:N/A:N/T:T/2026-06-11T16:16:59Z/",
"title": "SSVC"
}
],
"product_status": {
"fixed": [
"CSAFPID-0002",
"CSAFPID-0010"
],
"known_affected": [
"CSAFPID-0001",
"CSAFPID-0009"
]
},
"references": [
{
"category": "external",
"summary": "www.cve.org",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-54104"
},
{
"category": "external",
"summary": "epds.gao.gov",
"url": "https://epds.gao.gov/"
},
{
"category": "external",
"summary": "www.eds.cbca.gov",
"url": "https://www.eds.cbca.gov/login"
},
{
"category": "external",
"summary": "raw.githubusercontent.com",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
}
],
"release_date": "2026-06-18T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0001"
]
},
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0002"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0009"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0010"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"CSAFPID-0001",
"CSAFPID-0009"
]
}
],
"title": "U.S. GAO EPDS and CBCA EDS client-based privilege escalation"
},
{
"acknowledgments": [
{
"names": [
"Blake Rash"
],
"organization": "CISA"
}
],
"cve": "CVE-2026-54105",
"cwe": {
"id": "CWE-639",
"name": "Authorization Bypass Through User-Controlled Key"
},
"notes": [
{
"category": "summary",
"text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the \u0027update-profile/\u0027 API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary \u0027user_id\u0027 parameter and receive a JSON response containing account-specific information, including the associated email address.",
"title": "Description"
},
{
"category": "details",
"text": "SSVCv2/E:N/A:Y/T:P/2026-06-11T16:16:19Z/",
"title": "SSVC"
}
],
"product_status": {
"fixed": [
"CSAFPID-0002",
"CSAFPID-0010"
],
"known_affected": [
"CSAFPID-0001",
"CSAFPID-0009"
]
},
"references": [
{
"category": "external",
"summary": "raw.githubusercontent.com",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
},
{
"category": "external",
"summary": "www.cve.org",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-54105"
},
{
"category": "external",
"summary": "epds.gao.gov",
"url": "https://epds.gao.gov/"
},
{
"category": "external",
"summary": "www.eds.cbca.gov",
"url": "https://www.eds.cbca.gov/login"
}
],
"release_date": "2026-06-18T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0001"
]
},
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0002"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0009"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0010"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-0001",
"CSAFPID-0009"
]
}
],
"title": "U.S. GAO EPDS and CBCA EDS user information disclosure"
},
{
"acknowledgments": [
{
"names": [
"Blake Rash"
],
"organization": "CISA"
}
],
"cve": "CVE-2026-54106",
"cwe": {
"id": "CWE-940",
"name": "Improper Verification of Source of a Communication Channel"
},
"notes": [
{
"category": "summary",
"text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.",
"title": "Description"
},
{
"category": "details",
"text": "SSVCv2/E:P/A:N/T:P/2026-06-11T19:54:32Z/",
"title": "SSVC"
}
],
"product_status": {
"fixed": [
"CSAFPID-0002",
"CSAFPID-0010"
],
"known_affected": [
"CSAFPID-0001",
"CSAFPID-0009"
]
},
"references": [
{
"category": "external",
"summary": "raw.githubusercontent.com",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
},
{
"category": "external",
"summary": "www.cve.org",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-54106"
},
{
"category": "external",
"summary": "epds.gao.gov",
"url": "https://epds.gao.gov/"
},
{
"category": "external",
"summary": "www.eds.cbca.gov",
"url": "https://www.eds.cbca.gov/login"
}
],
"release_date": "2026-06-18T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0001"
]
},
{
"category": "vendor_fix",
"date": "2026-02-22T00:00:00Z",
"details": "Fixed on or about 2026-02-22.",
"product_ids": [
"CSAFPID-0002"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0009"
]
},
{
"category": "vendor_fix",
"date": "2026-03-19T00:00:00Z",
"details": "Fixed on or about 2026-03-19.",
"product_ids": [
"CSAFPID-0010"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"CSAFPID-0001",
"CSAFPID-0009"
]
}
],
"title": "U.S. GAO EPDS and CBCA EDS network access control bypass"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…