CVE-2026-54103
Government Accountability Office Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS) 취약점
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
- 대응 우선순위
- 점검
- CVSS
- 9.3
- EPSS
- 0.77% 백분위 52.0% · 2026.07.28 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.19