CVE-2026-54106
MEDIUM
4.7
CVSS 3.1
Description
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.
Metadata
Severity & Metrics
4.7
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Civilian Board of Contract Appeals | Electronic Docketing System (EDS) | — | 0 < 2026-03-19, 2026-03-19 |
| Government Accountability Office | Electronic Protest Docketing System (EPDS) | — | 0 < 2026-02-22, 2026-02-22 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-940 | cna | CWE-940 Improper Verification of Source of a Communication Channel |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.1 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
| 4.7 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
References (4)