Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover. | |
| Title | Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API | |
| First Time appeared |
Modoboa
Modoboa modoboa |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:modoboa:modoboa:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modoboa
Modoboa modoboa |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-29T17:14:27.634Z
Reserved: 2026-06-23T01:22:22.572Z
Link: CVE-2026-56780
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T19:30:02Z
Weaknesses