CBP’s 7-Year Security Blind Spot: What the Agency Won’t Explain About Its Undetected Vulnerability

A flat, institutional graphic styled like a federal IT security audit exhibit. The centerpiece is a bureaucratic form or system diagram labeled "PRIVILEGED ACCESS: ALL USERS" with a large red stamp reading "UNDETECTED — 7 YEARS" across it. In the corner, a small checkbox labeled "Internal Security Review" is conspicuously unchecked. The overall aesthetic is deadpan government document — muted beige or pale green background, navy blue text, red stamp ink. No photography, no dramatic lighting, no people. The humor is in the mundane institutional framing of a catastrophic security failure. Flat design, dry, bureaucratic.

A powerful administrative account was created inside U.S. Customs and Border Protection‘s computer network in 2019. For seven years, that account allowed any of CBP’s 76,000 network users—including contractors, visiting personnel from other agencies, and potentially anyone with network access—to perform privileged administrative tasks. They could reset passwords. They could modify user permissions. They could change security configurations.

CBP didn’t catch it. A federal audit did.

On September 4, 2026, the Department of Homeland Security Office of Inspector General released an audit of CBP’s information technology access controls. Buried in the report is a finding so significant that it demands an explanation CBP has not provided: How did a critical vulnerability created in 2019 remain undetected for seven years, until an outside auditor discovered it during routine testing?

The OIG report provides only a partial answer, using the bureaucratic language of “monitoring gaps” and “lacking tools to detect unexpected configurations.” But that explanation raises more questions than it answers—and CBP has declined to provide clarification.

The Vulnerability: Widespread Privileged Access

Service accounts are special non-human accounts used by IT systems to perform automated functions. Unlike regular user accounts, service accounts typically have elevated privileges—they need to perform powerful tasks that regular users shouldn’t be able to do.

In principle, service accounts are carefully controlled. Only authorized applications should be able to use them. Regular users should never have access to them.

But in CBP’s case, all 76,000 network users had access to one highly privileged service account. 

“We identified a major vulnerability that attackers could have used to compromise CBP’s network,” the OIG stated flatly.

With this access, an attacker could:

  • Change account passwords across CBP’s network
  • Add or remove user access permissions
  • Modify security configurations
  • Cover their tracks by manipulating audit logs (potentially)

The implications are staggering. Every one of CBP’s 76,000 network users—including contractors, visiting personnel from other DHS components, and outside consultants—could perform administrative functions that should be restricted to a handful of vetted security professionals.

“If CBP does not safeguard privileged accounts, attackers could use elevated permissions to access sensitive resources and perform powerful tasks, such as changing passwords and security settings,” the OIG warned.

Seven Years of Exposure

The vulnerability was created in 2019. The audit fieldwork took place from October 2024 through December 2025. CBP remained unaware of the problem for approximately seven years.

“CBP immediately fixed the issue once notified,” the OIG report states. But this formulation obscures a critical question: Why did it take seven years for CBP to discover something an auditor found during standard testing?

The answer, according to CBP, is monitoring gaps.

“According to CBP, its privileged account vulnerabilities occurred due to human error and challenges associated with monitoring account access changes over time, such as lacking tools to detect unexpected configurations,” the OIG noted.

CBP also provided a timeline. “In recent years, CBP implemented new monitoring capabilities,” the report states. “However, according to CBP, these new controls were not as effective for older accounts.”

This raises immediate questions:

  • When exactly were these new monitoring capabilities implemented? If “recent years” means 2023 or 2024, then CBP had at least one or two years between deploying new monitoring and the audit discovering this vulnerability. Why didn’t those new tools catch it?
  • What about 2019 through 2022? What was CBP’s monitoring posture during those years?
  • If CBP lacked tools to detect unexpected configurations in 2019-2022, how did the auditors detect this vulnerability? What did they use that CBP didn’t have?

CBP has not answered these questions. Bureaucracy Times submitted follow-up questions to CBP’s public affairs office asking for specifics on monitoring capabilities, timeline of deployment, and the auditor’s detection methodology. The agency declined to provide additional information.

The Audit Process That Found It

The OIG didn’t discover this vulnerability through passive monitoring or review of CBP’s security logs. They found it through active testing.

“We performed technical assessments and penetration testing of CBP’s domain,” the audit states. “We completed penetration testing and configuration, vulnerability, and Active Directory assessments of the CBP Directory Services platform to determine how CBP manages vulnerabilities and security settings.”

In other words: The OIG actually tried to break into CBP’s system, and in doing so, found this vulnerability. This is standard practice for security audits, but it underscores the key point—this wasn’t a passive discovery. This was an active security assessment, and it immediately surfaced the problem.

The Larger Context: Other Privilege Escalation Paths

The service account vulnerability was the most egregious finding, but it wasn’t the only one.

The OIG also identified “more than 100 paths that would have allowed some users to elevate their permissions to an administrator level without proper authorization.”

Over 100. Separate. Attack. Paths.

An attacker could take over a regular user account, use one of these 100+ paths to escalate their privileges to administrator level, and then move through CBP’s network performing additional attacks “without CBP’s awareness.”

CBP users could:

  • Take over accounts of CBP teams monitoring insider threats
  • Take over user accounts with access to sensitive law enforcement information
  • Obtain CBP officer-level access to shared drives at ports of entry
  • Become administrators of mobile device management software

Again, all this was possible because CBP had “all users…incorrectly granted permission to perform privileged account or sensitive functions, although CBP is required to limit privileged access to the minimum level necessary for mission needs.”

The underlying problem is the same: CBP’s access architecture allows far too many people to perform far too many privileged actions.

Why This Matters

CBP is a high-value target for attackers. The agency manages biometric databases, law enforcement information, border security intelligence, and travel documents. In June 2025, CBP experienced a cybersecurity incident where hackers stole CBP employee data.

A network architecture where 76,000 users have access to privileged administrative functions is an invitation for attackers.

If an external hacker compromised any single CBP employee’s credentials—through phishing, credential theft, or a supply chain attack—they would immediately have access to powerful administrative capabilities. They could create backdoors, modify security settings, and cover their tracks.

Or, if an insider threat actor wanted to abuse CBP’s systems, they wouldn’t need to steal credentials from a system administrator. They would already have the capabilities they needed.

The fact that CBP maintained this configuration for seven years—through two presidential administrations, through multiple cybersecurity incidents at other federal agencies, through evolving hacking techniques and increased threat awareness—suggests either:

  1. CBP’s security culture doesn’t prioritize preventive security architecture
  2. CBP lacked the technical expertise to recognize this problem
  3. CBP’s monitoring and testing processes were inadequate
  4. Some combination of the above

The OIG audit documents the problem. It does not explain how CBP allowed it to persist for seven years.

CBP’s Timeline for Fixing It

In response to the OIG audit, CBP provided corrective action plans. For the service account vulnerability and the 100+ privilege escalation paths, CBP’s response includes:

  1. Comprehensive audit of the EVERYONE Active Directory group (completed, per CBP)
  2. Removal of all identified excessive privileges (completed, per CBP)
  3. Implementation of monitoring controls to detect future changes to these permissions (in progress, per OIG analysis)
  4. Evaluation of the 100+ identified attack paths (in progress, per OIG analysis)

CBP claims it had already remediated the specific service account vulnerability and performed a validation scan to confirm no similar misconfigurations existed. It provided evidence to the OIG on April 4, 2025, and additional evidence on July 22, 2026.

However, the OIG analysis of CBP’s responses includes this language: “To meet the intent of the recommendation, we need documentation that demonstrates how these new alerts are monitored and the actions taken to respond to any alerts.”

Translation: CBP says it implemented monitoring, but it hasn’t demonstrated that anyone is actually watching the monitors or acting on alerts. This is a critical distinction—a monitor that no one watches is just a log file.

Similarly, regarding the 100+ attack paths: “CBP has only provided evidence demonstrating its analysis and remediation of the EVERYONE group attack paths. We need documentation showing all 100-plus attack paths were analyzed and any unnecessary accesses were adjusted.”

Translation: CBP fixed the one big problem but hasn’t demonstrated it fixed all 100+ of them.

What Remains Unexplained

CBP’s public response to the audit consists of a standard agency concurrence memo. In that memo, CBP acknowledges “CBP has defined controls and processes to secure privileged accounts” and notes that the agency “implemented an access management system to periodically review and approve privileged and service account access permissions.”

But if CBP had defined controls, defined processes, and an access management system, how did the service account remain misconfigured for seven years?

CBP does not answer this question.

The agency also does not explain:

  • Account creation and authorization: Who created this service account in 2019? Was there a change control process? Was it documented? If the account was created for a specific business need and then that need changed, who was responsible for decommissioning it?
  • Access logs: Did CBP maintain audit logs of who accessed this account and when? If so, was there any suspicious activity during the seven years? If not, why not?
  • Monitoring capabilities before 2023: What monitoring did CBP have in place from 2019-2022? Why was it ineffective? Were there budget constraints, staffing limitations, or technical limitations that prevented better monitoring?
  • The penetration testing question: If the auditors could find this vulnerability with penetration testing, why didn’t CBP’s own security teams perform penetration testing? Is CBP not conducting regular penetration tests of its infrastructure? How often?
  • Risk acceptance: Did CBP know about this vulnerability and accept the risk? Or was it simply unknown? If unknown, does CBP conduct any pro-active security assessments, or only reactive ones?

These are legitimate accountability questions that the public and Congress should have answered.

A Broader Pattern

This vulnerability exists within a larger context of CBP access control failures documented in the same audit.

CBP failed to disable accounts for separated personnel in a timely manner (20 percent of sampled employee accounts, 15 percent of contractor accounts).

CBP failed to remove unneeded access for transferred employees (17 percent retained unnecessary access).

CBP did not enroll all applications in its centralized access management system and had no process to enforce a 2023 modernization directive that required such enrollment.

CBP was unaware of all applications running on its network.

These failures—the service account vulnerability, the 100+ attack paths, the account disablement failures, the transferred employee access retention—are not isolated incidents. They suggest a systemic weakness in CBP’s ability to maintain secure access controls across its infrastructure.

The OIG has documented the problems. CBP has agreed to fix them. But the fundamental question remains: Why did it take a federal audit to identify vulnerabilities that CBP should have found through its own security processes?

That’s the story CBP won’t explain.


References and Links

Full OIG Report (OIG-26-28): CBP’s IT Access Control Deficiencies Introduced Critical Risk to IT Systems and Sensitive Information — OIG-26-28-Sep26.pdf — Released September 4, 2026 by the DHS Office of Inspector General

– **OIG Report Section:** Key Finding 1: “CBP Did Not Consistently Secure Privileged Accounts and Sensitive Information” (pages 2-4 of report)

DHS OIG Homepage: www.oig.dhs.gov

Relevant DHS Policy (referenced in audit):

  • DHS 4300A: Information Technology System Security Program, Sensitive Systems (v. 13.4, December 2024)
  • NIST SP 800-53, Revision 5: Security and Privacy Controls for Information Systems and Organizations

Related Incident:

  – June 2025 CBP Cybersecurity Incident: Mentioned in OIG report as context for threat environment. Full details of incident not available in public reporting.


Editor’s Notes

– CBP was asked for specific details about: (1) the service account’s creation, purpose, and authorization process; (2) audit logs covering the 2019-2025 period; (3) the timeline of monitoring capability deployment; (4) whether penetration testing was routinely conducted; and (5) whether this vulnerability was previously known but accepted as a risk. CBP declined to provide additional information beyond the written response to the OIG audit.

– The OIG report explicitly notes about CBP’s account remediation: “An audit log review was conducted which confirmed that the misconfigured account was not subjected to unauthorized use.” This suggests that while the vulnerability existed, there is no evidence it was exploited during the seven-year period. However, the OIG did not disclose whether access logs existed for the entire 2019-2025 period or only for a more recent timeframe.

– The terminology “EVERYONE Active Directory group” is technical jargon for a Windows domain group that, by default, includes all users on a network. In this case, it should not have included permission to perform the privileged actions that CBP had granted it.

Fediverse reactions

Discover more from Bureaucracy Times

Subscribe to get the latest posts sent to your email.