CVE-2026-54104
Government Accountability Office Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS) 취약점
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.
- 대응 우선순위
- 점검
- CVSS
- 8.7
- EPSS
- 0.72% 백분위 50.3% · 2026.07.28 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.19