← Terug naar overzicht

Gophish versions through 0.12.1 contain a vulnerability in the API authentication middleware that fails to enforce account lockout and password change requirements. Attackers who possess valid API keys can bypass these security controls entirely, retaining full API access even when their account has been locked or flagged for a mandatory password change. This flaw undermines administrative security measures designed to restrict compromised or non-compliant accounts. The vulnerability is tracked as CVE-2026-82269 and affects the middleware.go component of the Gophish codebase. Since Gophish is a widely used phishing simulation and security awareness platform, exploitation could allow unauthorized continued access to phishing campaign data and configurations. No patch version is explicitly mentioned, but the issue has been reported via GitHub issues and VulnCheck advisories.

Affected products

  • Gophish 0.12.1

Related CVE's

  • CVE-2026-82269

Categories

  • Identity & Access
  • Security Tools
  • Web Technologies