{ "document": { "category": "csaf_vex", "csaf_version": "2.0", "lang": "en-US", "publisher": { "category": "coordinator", "contact_details": "https://www.cisa.gov/report", "issuing_authority": "CISA", "name": "CISA", "namespace": "https://www.cisa.gov/" }, "title": "U.S. GAO EPDS and CBCA EDS multiple vulnerabilities", "tracking": { "current_release_date": "2026-06-18T15:45:16Z", "generator": { "engine": { "name": "VINCE-NT", "version": "1.15.0+build.89" } }, "id": "VA-26-169-01", "initial_release_date": "2026-06-18T15:45:16Z", "status": "final", "version": "1.0.0", "revision_history": [ { "number": "1.0.0", "summary": "Initial publication", "date": "2026-06-18T15:45:16Z" } ] }, "distribution": { "tlp": { "label": "WHITE" } }, "notes": [ { "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).", "title": "Legal Notice", "category": "legal_disclaimer" }, { "text": "Worldwide", "title": "Countries and Areas Deployed", "category": "other" }, { "text": "Information Technology", "title": "Critical Infrastructure Sectors", "category": "other" }, { "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) contained multiple vulnerabilities. In the worst case, a remote, unauthenticated attacker could change all users' passwords and gain administrative privileges.", "title": "Risk Evaluation", "category": "summary" }, { "text": "These vulnerabilities were confirmed to be fixed as of 2026-03-19.", "title": "Recommended Practices", "category": "general" }, { "text": "United States", "title": "Company Headquarters Location", "category": "other" } ], "references": [ { "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json", "summary": "Vulnerability Advisory VA-26-169-01 CSAF", "category": "self" } ] }, "product_tree": { "branches": [ { "category": "vendor", "name": "Government Accountability Office", "branches": [ { "category": "product_name", "name": "Electronic Protest Docketing System (EPDS)", "branches": [ { "category": "product_version_range", "name": "<2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22", "product_id": "CSAFPID-0001" } }, { "category": "product_version", "name": "2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22", "product_id": "CSAFPID-0002" } } ] }, { "category": "product_name", "name": "Electronic Protest Docketing System (EPDS)", "branches": [ { "category": "product_version_range", "name": "<2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22", "product_id": "CSAFPID-0003" } }, { "category": "product_version", "name": "2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22", "product_id": "CSAFPID-0004" } } ] }, { "category": "product_name", "name": "Electronic Protest Docketing System (EPDS)", "branches": [ { "category": "product_version_range", "name": "<2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22", "product_id": "CSAFPID-0005" } }, { "category": "product_version", "name": "2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22", "product_id": "CSAFPID-0006" } } ] }, { "category": "product_name", "name": "Electronic Protest Docketing System (EPDS)", "branches": [ { "category": "product_version_range", "name": "<2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) <2026-02-22", "product_id": "CSAFPID-0007" } }, { "category": "product_version", "name": "2026-02-22", "product": { "name": "Government Accountability Office Electronic Protest Docketing System (EPDS) 2026-02-22", "product_id": "CSAFPID-0008" } } ] } ] }, { "category": "vendor", "name": "Civilian Board of Contract Appeals", "branches": [ { "category": "product_name", "name": "Electronic Docketing System (EDS)", "branches": [ { "category": "product_version_range", "name": "<2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19", "product_id": "CSAFPID-0009" } }, { "category": "product_version", "name": "2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19", "product_id": "CSAFPID-0010" } } ] }, { "category": "product_name", "name": "Electronic Docketing System (EDS)", "branches": [ { "category": "product_version_range", "name": "<2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19", "product_id": "CSAFPID-0011" } }, { "category": "product_version", "name": "2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19", "product_id": "CSAFPID-0012" } } ] }, { "category": "product_name", "name": "Electronic Docketing System (EDS)", "branches": [ { "category": "product_version_range", "name": "<2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19", "product_id": "CSAFPID-0013" } }, { "category": "product_version", "name": "2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19", "product_id": "CSAFPID-0014" } } ] }, { "category": "product_name", "name": "Electronic Docketing System (EDS)", "branches": [ { "category": "product_version_range", "name": "<2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) <2026-03-19", "product_id": "CSAFPID-0015" } }, { "category": "product_version", "name": "2026-03-19", "product": { "name": "Civilian Board of Contract Appeals Electronic Docketing System (EDS) 2026-03-19", "product_id": "CSAFPID-0016" } } ] } ] } ] }, "vulnerabilities": [ { "cve": "CVE-2026-54103", "cwe": { "id": "CWE-306", "name": "Missing Authentication for Critical Function" }, "notes": [ { "category": "summary", "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:Y/T:T/2026-06-11T16:17:36Z/" } ], "title": "U.S. GAO EPDS and CBCA EDS unauthenticated password change", "product_status": { "known_affected": [ "CSAFPID-0001", "CSAFPID-0009" ], "fixed": [ "CSAFPID-0002", "CSAFPID-0010" ] }, "references": [ { "category": "external", "summary": "raw.githubusercontent.com", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54103" }, { "category": "external", "summary": "epds.gao.gov", "url": "https://epds.gao.gov/" }, { "category": "external", "summary": "www.eds.cbca.gov", "url": "https://www.eds.cbca.gov/login" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0001", "CSAFPID-0009" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0001" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0002" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0009" ], "date": "2026-03-19T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0010" ], "date": "2026-03-19T00:00:00Z" } ], "acknowledgments": [ { "organization": "CISA", "names": [ "Blake Rash" ] } ], "release_date": "2026-06-18T00:00:00Z" }, { "cve": "CVE-2026-54104", "cwe": { "id": "CWE-602", "name": "Client-Side Enforcement of Server-Side Security" }, "notes": [ { "category": "summary", "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:N/T:T/2026-06-11T16:16:59Z/" } ], "title": "U.S. GAO EPDS and CBCA EDS client-based privilege escalation", "product_status": { "known_affected": [ "CSAFPID-0001", "CSAFPID-0009" ], "fixed": [ "CSAFPID-0002", "CSAFPID-0010" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54104" }, { "category": "external", "summary": "epds.gao.gov", "url": "https://epds.gao.gov/" }, { "category": "external", "summary": "www.eds.cbca.gov", "url": "https://www.eds.cbca.gov/login" }, { "category": "external", "summary": "raw.githubusercontent.com", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0001", "CSAFPID-0009" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0001" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0002" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0009" ], "date": "2026-03-19T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0010" ], "date": "2026-03-19T00:00:00Z" } ], "acknowledgments": [ { "organization": "CISA", "names": [ "Blake Rash" ] } ], "release_date": "2026-06-18T00:00:00Z" }, { "cve": "CVE-2026-54105", "cwe": { "id": "CWE-639", "name": "Authorization Bypass Through User-Controlled Key" }, "notes": [ { "category": "summary", "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary 'user_id' parameter and receive a JSON response containing account-specific information, including the associated email address.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:Y/T:P/2026-06-11T16:16:19Z/" } ], "title": "U.S. GAO EPDS and CBCA EDS user information disclosure", "product_status": { "known_affected": [ "CSAFPID-0001", "CSAFPID-0009" ], "fixed": [ "CSAFPID-0002", "CSAFPID-0010" ] }, "references": [ { "category": "external", "summary": "raw.githubusercontent.com", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54105" }, { "category": "external", "summary": "epds.gao.gov", "url": "https://epds.gao.gov/" }, { "category": "external", "summary": "www.eds.cbca.gov", "url": "https://www.eds.cbca.gov/login" } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-0001", "CSAFPID-0009" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0001" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0002" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0009" ], "date": "2026-03-19T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0010" ], "date": "2026-03-19T00:00:00Z" } ], "acknowledgments": [ { "organization": "CISA", "names": [ "Blake Rash" ] } ], "release_date": "2026-06-18T00:00:00Z" }, { "cve": "CVE-2026-54106", "cwe": { "id": "CWE-940", "name": "Improper Verification of Source of a Communication Channel" }, "notes": [ { "category": "summary", "text": "The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:P/A:N/T:P/2026-06-11T19:54:32Z/" } ], "title": "U.S. GAO EPDS and CBCA EDS network access control bypass", "product_status": { "known_affected": [ "CSAFPID-0001", "CSAFPID-0009" ], "fixed": [ "CSAFPID-0002", "CSAFPID-0010" ] }, "references": [ { "category": "external", "summary": "raw.githubusercontent.com", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54106" }, { "category": "external", "summary": "epds.gao.gov", "url": "https://epds.gao.gov/" }, { "category": "external", "summary": "www.eds.cbca.gov", "url": "https://www.eds.cbca.gov/login" } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "CSAFPID-0001", "CSAFPID-0009" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0001" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-02-22.", "product_ids": [ "CSAFPID-0002" ], "date": "2026-02-22T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0009" ], "date": "2026-03-19T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed on or about 2026-03-19.", "product_ids": [ "CSAFPID-0010" ], "date": "2026-03-19T00:00:00Z" } ], "acknowledgments": [ { "organization": "CISA", "names": [ "Blake Rash" ] } ], "release_date": "2026-06-18T00:00:00Z" } ] }