Hard-Coded API Key Vulnerability in pH7Builder from pH7 Software
CVE-2026-108905

8.7HIGH

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108905?

The pH7Builder, a social dating CMS provided by pH7 Software, features a vulnerability where an attacker can exploit a hard-coded API key in Tool.class.php. This issue allows unauthenticated users to bypass API access checks by spoofing the Host header, specifically by sending a request with 'Host: localhost' and the private API key 'dev772277'. This vulnerability could expose sensitive information such as member emails, IP addresses, phone numbers, and bank account details, posing a significant risk to user privacy and data security.

Affected Version(s)

ph7builder 0 < 18.6.0

ph7builder 18.6.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haluk Baran AKBULUT (CyberMap Group)
.