CVE-2026-56780
HIGHModoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API
Title source: cnaDescription
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.
References (3)
Core 3
Core References
Patch patch
Patch Commit
https://github.com/modoboa/modoboa/commit/a1878c4920a6e47c3217c6ff1ed4a8753c202661
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/modoboa-insecure-direct-object-reference-in-account-password-change-api
Scores
CVSS v3
7.5
EPSS
0.0027
EPSS Percentile
18.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (2)
modoboa/modoboa
< 2.9.0
modoboa/modoboa
2.9.0
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026