# CVE-2026-54104 — Government Accountability Office Electronic Protest Docketing System (EPDS)

> As of 2026-06-19, CVE-2026-54104 is a HIGH-severity vulnerability in Government Accountability Office Electronic Protest Docketing System (EPDS), CVSS v3.1 8.8. No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-54104 as of 2026-06-19; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2026-06-19

## What is CVE-2026-54104?

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

The record classifies CVE-2026-54104 under weakness class [CWE-602](https://cwe.mitre.org/data/definitions/602.html). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 2 affected-product entries are recorded, across 2 vendors, listed below. The identifier was first published 109 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 8.8 — HIGH (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`)
- **CVSS v4.0 base score:** 8.7 (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`)
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 4.4/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-06-18, last modified 2026-06-19

## Is CVE-2026-54104 being exploited?

It currently carries a trending score of 30 in the Threadlinqs vulnerability feed.

## Affected products and versions

- **Government Accountability Office**: Electronic Protest Docketing System (EPDS)
- **Civilian Board of Contract Appeals**: Electronic Docketing System (EDS)

## How to fix CVE-2026-54104

No vendor patch reference has been recorded for CVE-2026-54104 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-54104

No threat campaign in the Threadlinqs corpus currently references CVE-2026-54104, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org. Last verified by Threadlinqs on 2026-06-19.

**Vulnerability database entry**

- [cve.org — vdb entry](https://www.cve.org/CVERecord?id=CVE-2026-54104)

**Issue tracking and product pages**

- [epds.gao.gov — product](https://epds.gao.gov/)
- [eds.cbca.gov — product](https://www.eds.cbca.gov/login)

**Other references**

- [raw.githubusercontent.com](https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-54104
Full detection coverage and IOCs for threats exploiting CVE-2026-54104 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
