Junglewise Threat Intelligence

CVE-2026-56780: Modoboa IDOR in account password change API

CVE-2026-56780 · Severity: high · CVSS 7.5 · Published 2026-06-29

Executive brief

Modoboa is an open-source mail hosting and management platform. A security flaw in the platform's account management interface allows a domain administrator to reset the password of any other user, including system-wide super-administrators. This could lead to a complete takeover of the entire mail server infrastructure by a malicious or compromised administrative account.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the 'PUT /api/v1/accounts/{pk}/password/' endpoint of Modoboa. The application fails to properly validate that the authenticated domain administrator has the authority to modify the specific user account identified by the primary key ({pk}) in the request. By manipulating this identifier, an attacker with low-level domain administrative privileges can reset the password of any user, including super-administrators, bypassing object-level access controls. This vulnerability is addressed in version 2.9.0.

Affected products

  • Modoboa Modoboa before 2.9.0

Timeline

  • 2026-05-27: patched: Fix merged into master branch via pull request 4038
  • 2026-06-29: disclosed: CVE published and NVD record created

References