Executive brief
The U.S. Government Accountability Office (GAO) and the Civilian Board of Contract Appeals (CBCA) use specialized docketing systems to manage legal protests and contract appeals. A security flaw in these systems allows an attacker who has already stolen administrator credentials to bypass network-based security restrictions by spoofing their location. This could allow unauthorized access to sensitive legal filings and administrative controls from restricted or untrusted networks.
Technical details
The vulnerability is classified as an improper verification of source (CWE-940) within the GAO EPDS and CBCA EDS platforms. The systems do not properly validate the 'X-Forwarded-For' HTTP header, which is commonly used to identify the originating IP address of a client connecting through a proxy. A remote attacker who has obtained valid administrator credentials can manipulate this header to spoof a trusted IP address, thereby bypassing network access control lists (ACLs) or IP-based authentication restrictions. This allows the attacker to log in from unauthorized network locations. Patches were released for EPDS on 2026-02-22 and for EDS on 2026-03-19.
Affected products
- Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) Versions before 2026-02-22
- Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) Versions before 2026-03-19
Timeline
- 2026-02-22: patched: GAO EPDS patch released
- 2026-03-19: patched: CBCA EDS patch released
- 2026-06-18: disclosed: NVD publication date