Authentication Bypass Vulnerability in phpIPAM by phpIPAM
CVE-2026-67602

9.3CRITICAL

Key Information:

Vendor

PHPipam

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-67602?

phpIPAM versions prior to 1.8.2 are susceptible to an authentication bypass vulnerability in the REST API. This flaw allows unauthenticated attackers to exploit an insecure object cache keying mechanism. The cache mechanism relies solely on lookup values, failing to incorporate the column being searched. This oversight permits an entry created during an app_id lookup to be misused in a subsequent app_code lookup. Consequently, attackers can leverage the numeric database row identifier as a de facto API token, granting unrestricted access to read, write, and delete critical IP address management records. It is vital for users to upgrade to version 1.8.2 to mitigate this risk.

Affected Version(s)

phpipam 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BENDIB MOHAMED ANIS
VulnCheck
.