---
id: CVE-2026-107270
title: >-
  Gophish through 0.12.1 contains an insecure direct object reference
  vulnerability that allows authenticated users to take over other users'
  groups, templates, landing pages and sending profiles
summary: >-
  Gophish through 0.12.1 contains an insecure direct object reference
  vulnerability that allows authenticated users to take over other users'
  groups, templates, landing pages and sending profiles. Attackers can supply
  another user's sequen…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-639
vendor: gophish
product: gophish
affected:
  - gophish <= 0.12.1
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:54.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107270'
references:
  - url: 'https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gophish/gophish'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/group.go#L28-L43
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/models/group.go#L194-L200
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gophish-through-0.12.1-object-takeover-via-client-supplied-id-on-api-create-endpoints
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T16:58:46.373114Z'
ingestedAt: '2026-10-07T16:38:22.227Z'
---

## Overview

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
