Executive brief
The U.S. Government Accountability Office (GAO) and the Civilian Board of Contract Appeals (CBCA) operate digital systems for managing legal protests and contract appeals. A security flaw in these systems allowed unauthorized individuals to access sensitive account details, such as user email addresses, by manipulating web requests. This could lead to the exposure of private contact information for government contractors and legal professionals using the platforms.
Technical details
The vulnerability is classified as an Insecure Direct Object Reference (IDOR) or Authorization Bypass Through User-Controlled Key (CWE-639) within the 'update-profile/' API endpoint. By supplying an arbitrary 'user_id' parameter in a network request, a remote, unauthenticated attacker can bypass authorization checks to retrieve JSON responses containing sensitive user data, specifically email addresses. The flaw stems from a failure to validate that the requesting user has the permission to view the profile associated with the provided ID. Patches were reportedly implemented in February and March 2026 for the respective systems.
Affected products
- Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) Versions prior to 2026-02-22
- Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) Versions prior to 2026-03-19
Timeline
- 2026-02-22: patched: GAO EPDS patched
- 2026-03-19: patched: CBCA EDS patched
- 2026-06-18: disclosed: NVD publication date