CVE-2026-56780
modoboa modoboa 취약점
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.
- 대응 우선순위
- 점검
- CVSS
- 7.7
- EPSS
- 0.27% 백분위 18.2% · 2026.07.20 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.30