CVE-2026-56780
EUVD-2026-4015529.06.2026, 18:16
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.EnginsightEarly Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| modoboa | modoboa | 𝑥 < 2.9.0 | CNA |
Common Weakness Enumeration