Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover. | |
| Title | Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API | |
| First Time appeared |
Modoboa
Modoboa modoboa |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:modoboa:modoboa:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modoboa
Modoboa modoboa |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-29T17:14:27.634Z
Reserved: 2026-06-23T01:22:22.572Z
Link: CVE-2026-56780
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T19:30:02Z