---
id: CVE-2026-82269
title: >-
  Gophish through 0.12.1 fails to enforce account lockout and password change
  requirements in the API authentication middleware
summary: >-
  Gophish through 0.12.1 fails to enforce account lockout and password change
  requirements in the API authentication middleware. Attackers with valid API
  keys can bypass these security controls and retain full API access even when
  their ac…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-288
published: '2026-08-28'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:43.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82269'
references:
  - url: 'https://github.com/gophish/gophish'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gophish/gophish/blob/95618469799295e2c0fec980805a2dfbb818816b/middleware/middleware.go
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gophish/gophish/issues/9440'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gophish-account-lockout-and-forced-password-change-bypassable-via-api-key
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gophish/gophish/issues/9440'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00384
epssPercentile: 0.29671
ingestedAt: '2026-09-23T17:28:14.812Z'
vendor: gophish
product: gophish
affected:
  - gophish <= 0.12.1
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-28T20:29:13.644317Z'
---

## Overview

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
