VA-26-169-01

Vulnerability from csaf_cisa - Published: 2026-06-18 15:45 - Updated: 2026-06-18 15:45
Summary
U.S. GAO EPDS and CBCA EDS multiple vulnerabilities
Notes
Legal Notice: All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).
Countries and Areas Deployed: Worldwide
Critical Infrastructure Sectors: Information Technology
Risk Evaluation: The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users' passwords and gain administrative privileges.
Recommended Practices: These vulnerabilities were confirmed to be fixed as of 2026-03-19.
Company Headquarters Location: United States
CWE-306 - Missing Authentication for Critical Function
Affected products
Product Identifier Version Remediation
Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22
Government Accountability Office / Electronic Protest Docketing System (EPDS)
<2026-02-22
Vendor Fix
Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19
Civilian Board of Contract Appeals / Electronic Docketing System (EDS)
<2026-03-19
Vendor Fix
Product Identifier Version Remediation
Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22
Government Accountability Office / Electronic Protest Docketing System (EPDS)
2026-02-22
Vendor Fix
Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19
Civilian Board of Contract Appeals / Electronic Docketing System (EDS)
2026-03-19
Vendor Fix
CWE-602 - Client-Side Enforcement of Server-Side Security
Affected products
Known affected 2 products, the same list as for CVE-2026-54103
Fixed 2 products, the same list as for CVE-2026-54103
CWE-639 - Authorization Bypass Through User-Controlled Key
Affected products
Known affected 2 products, the same list as for CVE-2026-54103
Fixed 2 products, the same list as for CVE-2026-54103
CWE-940 - Improper Verification of Source of a Communication Channel
Affected products
Known affected 2 products, the same list as for CVE-2026-54103
Fixed 2 products, the same list as for CVE-2026-54103
Acknowledgments

{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).",
        "title": "Legal Notice"
      },
      {
        "category": "other",
        "text": "Worldwide",
        "title": "Countries and Areas Deployed"
      },
      {
        "category": "other",
        "text": "Information Technology",
        "title": "Critical Infrastructure Sectors"
      },
      {
        "category": "summary",
        "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users\u0027 passwords and gain administrative privileges.",
        "title": "Risk Evaluation"
      },
      {
        "category": "general",
        "text": "These vulnerabilities were confirmed to be fixed as of 2026-03-19.",
        "title": "Recommended Practices"
      },
      {
        "category": "other",
        "text": "United States",
        "title": "Company Headquarters Location"
      }
    ],
    "publisher": {
      "category": "coordinator",
      "contact_details": "https://www.cisa.gov/report",
      "issuing_authority": "CISA",
      "name": "CISA",
      "namespace": "https://www.cisa.gov/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Vulnerability Advisory VA-26-169-01 CSAF",
        "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
      }
    ],
    "title": "U.S. GAO EPDS and CBCA EDS multiple vulnerabilities",
    "tracking": {
      "current_release_date": "2026-06-18T15:45:16Z",
      "generator": {
        "engine": {
          "name": "VINCE-NT",
          "version": "1.15.0+build.89"
        }
      },
      "id": "VA-26-169-01",
      "initial_release_date": "2026-06-18T15:45:16Z",
      "revision_history": [
        {
          "date": "2026-06-18T15:45:16Z",
          "number": "1.0.0",
          "summary": "Initial publication"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
                  "product_id": "CSAFPID-0001"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0002"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
                  "product_id": "CSAFPID-0003"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0004"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
                  "product_id": "CSAFPID-0005"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0006"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) \u003c2026-02-22",
                  "product_id": "CSAFPID-0007"
                }
              },
              {
                "category": "product_version",
                "name": "2026-02-22",
                "product": {
                  "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22",
                  "product_id": "CSAFPID-0008"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Protest Docketing System (EPDS)"
          }
        ],
        "category": "vendor",
        "name": "Government Accountability Office"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
                  "product_id": "CSAFPID-0009"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0010"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
                  "product_id": "CSAFPID-0011"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0012"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
                  "product_id": "CSAFPID-0013"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0014"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) \u003c2026-03-19",
                  "product_id": "CSAFPID-0015"
                }
              },
              {
                "category": "product_version",
                "name": "2026-03-19",
                "product": {
                  "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19",
                  "product_id": "CSAFPID-0016"
                }
              }
            ],
            "category": "product_name",
            "name": "Electronic Docketing System (EDS)"
          }
        ],
        "category": "vendor",
        "name": "Civilian Board of Contract Appeals"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54103",
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the \u0027/update-profile/N\u0027 API endpoint. A remote, unauthenticated attacker could change an arbitrary user\u0027s password.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:N/A:Y/T:T/2026-06-11T16:17:36Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54103"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS unauthenticated password change"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54104",
      "cwe": {
        "id": "CWE-602",
        "name": "Client-Side Enforcement of Server-Side Security"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the \u0027epds_role_id\u0027 parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:N/A:N/T:T/2026-06-11T16:16:59Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54104"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        },
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS client-based privilege escalation"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54105",
      "cwe": {
        "id": "CWE-639",
        "name": "Authorization Bypass Through User-Controlled Key"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the \u0027update-profile/\u0027 API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary \u0027user_id\u0027 parameter and receive a JSON response containing account-specific information, including the associated email address.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:N/A:Y/T:P/2026-06-11T16:16:19Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54105"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS user information disclosure"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Blake Rash"
          ],
          "organization": "CISA"
        }
      ],
      "cve": "CVE-2026-54106",
      "cwe": {
        "id": "CWE-940",
        "name": "Improper Verification of Source of a Communication Channel"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:P/A:N/T:P/2026-06-11T19:54:32Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002",
          "CSAFPID-0010"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0009"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "raw.githubusercontent.com",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54106"
        },
        {
          "category": "external",
          "summary": "epds.gao.gov",
          "url": "https://epds.gao.gov/"
        },
        {
          "category": "external",
          "summary": "www.eds.cbca.gov",
          "url": "https://www.eds.cbca.gov/login"
        }
      ],
      "release_date": "2026-06-18T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-22T00:00:00Z",
          "details": "Fixed on or about 2026-02-22.",
          "product_ids": [
            "CSAFPID-0002"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0009"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-03-19T00:00:00Z",
          "details": "Fixed on or about 2026-03-19.",
          "product_ids": [
            "CSAFPID-0010"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0009"
          ]
        }
      ],
      "title": "U.S. GAO EPDS and CBCA EDS network access control bypass"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…