Access Control Flaw in phpSysInfo Affects System Security
CVE-2026-55584
7.5HIGH
What is CVE-2026-55584?
phpSysInfo, a PHP script for displaying system information, contains an access control flaw in versions before 3.4.6. The vulnerability arises from the software's reliance on the X-Forwarded-For and Client-IP HTTP headers, which can be controlled by an attacker. This allows a remote unauthenticated individual to impersonate a trusted client and gain unauthorized access to sensitive details such as hostname, kernel, CPU, memory, filesystem, and network-interface information. The issue has been addressed in version 3.4.6.
Affected Version(s)
phpsysinfo < 3.4.6
