Back to overview

CVE-2026-54104

HIGH
8.8
CVSS 3.1
Description
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

Metadata

CVE ID
CVE-2026-54104
State
PUBLISHED
Assigner
cisa-cg
Reserved
2026-06-11 19:41 UTC
Published
2026-06-18 16:12 UTC
Last updated
2026-06-19 03:56 UTC
Primary CWE
CWE-602
CWE-602 Client-Side Enforcement of Server-Side Security
Vendor / Product
Government Accountability Office / Electronic Protest Docketing System (EPDS)
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Civilian Board of Contract Appeals Electronic Docketing System (EDS) 0 < 2026-03-19, 2026-03-19
Government Accountability Office Electronic Protest Docketing System (EPDS) 0 < 2026-02-22, 2026-02-22
Weakness (CWE)
CWESourceDescription
CWE-602 cna CWE-602 Client-Side Enforcement of Server-Side Security
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview