Missing Object-Level Authorization in Phproject REST API by Alanaktion
CVE-2026-104991
7.1HIGH
What is CVE-2026-104991?
The vulnerability in Phproject prior to version 1.8.7 creates a significant security risk as it allows authenticated users with valid API keys to bypass critical authorization checks on REST API issue endpoints. This flaw enables unauthorized access to sensitive issue content and associated comments, including personal details like owner and author email addresses. Moreover, attackers can exploit this weakness to post unauthorized comments on issues, undermining the integrity of the system and potentially leading to data exposure.
Affected Version(s)
phproject 1.1.6 < 1.8.7
