Executive brief
The U.S. Government Accountability Office (GAO) and the Civilian Board of Contract Appeals (CBCA) use electronic docketing systems to manage legal protests and contract appeals. A security flaw in these systems allows a registered user to gain unauthorized administrative privileges by manipulating data sent from their browser. This could allow an attacker to access sensitive legal documents, modify case records, or disrupt official government proceedings.
Technical details
The vulnerability is classified as Client-Side Enforcement of Server-Side Security (CWE-602). The EPDS and EDS platforms fail to validate the 'epds_role_id' parameter on the server side, instead relying on values provided by the client. A remote attacker with low-privileged authenticated access can intercept and modify this parameter to assume higher-level roles. Successful exploitation results in a full compromise of confidentiality, integrity, and availability within the context of the docketing systems. Patches were released in February and March 2026 for the respective systems.
Affected products
- Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) Versions prior to 2026-02-22
- Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) Versions prior to 2026-03-19
Timeline
- 2026-02-22: patched: GAO EPDS patched
- 2026-03-19: patched: CBCA EDS patched
- 2026-06-18: disclosed: Initial NVD publication