Missing Object-Level Authorization in Phproject REST API by Alanaktion
CVE-2026-104991

7.1HIGH

Key Information:

Vendor

Alanaktion

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104991?

The vulnerability in Phproject prior to version 1.8.7 creates a significant security risk as it allows authenticated users with valid API keys to bypass critical authorization checks on REST API issue endpoints. This flaw enables unauthorized access to sensitive issue content and associated comments, including personal details like owner and author email addresses. Moreover, attackers can exploit this weakness to post unauthorized comments on issues, undermining the integrity of the system and potentially leading to data exposure.

Affected Version(s)

phproject 1.1.6 < 1.8.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alisher Qarshibayev
VulnCheck
.