Executive brief
The U.S. Government Accountability Office (GAO) and the Civilian Board of Contract Appeals (CBCA) use electronic docketing systems to manage legal protests and contract appeals. A security flaw in these systems allows anyone on the internet to change any user's password without needing to log in first. This could lead to unauthorized access to sensitive legal filings, disruption of government proceedings, and full account takeover of system users.
Technical details
The vulnerability is classified as a missing authentication for a critical function (CWE-306) within the '/update-profile/N' API endpoint. The application fails to verify the identity or session of a requester before processing password update commands. A remote, unauthenticated attacker can exploit this by sending a crafted request to the vulnerable endpoint to change the password of any targeted user account. This provides a direct path to full account takeover. The issue has been addressed in the GAO EPDS as of February 22, 2026, and in the CBCA EDS as of March 19, 2026.
Affected products
- Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) Versions prior to 2026-02-22
- Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) Versions prior to 2026-03-19
Timeline
- 2026-02-22: patched: GAO EPDS patch date
- 2026-03-19: patched: CBCA EDS patch date
- 2026-06-18: disclosed