Back to overview

CVE-2026-54106

MEDIUM
4.7
CVSS 3.1
Description
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.

Metadata

CVE ID
CVE-2026-54106
State
PUBLISHED
Assigner
cisa-cg
Reserved
2026-06-11 19:41 UTC
Published
2026-06-18 16:13 UTC
Last updated
2026-06-18 16:13 UTC
Primary CWE
CWE-940
CWE-940 Improper Verification of Source of a Communication C…
Vendor / Product
Government Accountability Office / Electronic Protest Docketing System (EPDS)
Sources
cve.org  ·  NVD

Severity & Metrics

4.7 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Affected products (2)
VendorProductPlatformVersions
Civilian Board of Contract Appeals Electronic Docketing System (EDS) 0 < 2026-03-19, 2026-03-19
Government Accountability Office Electronic Protest Docketing System (EPDS) 0 < 2026-02-22, 2026-02-22
Weakness (CWE)
CWESourceDescription
CWE-940 cna CWE-940 Improper Verification of Source of a Communication Channel
CVSS scores (2)
ScoreSeverityVersionSourceVector
5.1 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
4.7 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Back to overview