Access Control Flaw in phpSysInfo Affects System Security
CVE-2026-55584

7.5HIGH

Key Information:

Vendor

PHPsysinfo

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55584?

phpSysInfo, a PHP script for displaying system information, contains an access control flaw in versions before 3.4.6. The vulnerability arises from the software's reliance on the X-Forwarded-For and Client-IP HTTP headers, which can be controlled by an attacker. This allows a remote unauthenticated individual to impersonate a trusted client and gain unauthorized access to sensitive details such as hostname, kernel, CPU, memory, filesystem, and network-interface information. The issue has been addressed in version 3.4.6.

Affected Version(s)

phpsysinfo < 3.4.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.