Information Disclosure in phpIPAM by Vendor phpIPAM
CVE-2026-75105

8.7HIGH

Key Information:

Vendor

PHPipam

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-75105?

The phpIPAM application prior to version 1.8.2 contains a flaw in its temporary share functionality. Specifically, the system fails to authenticate that a requested IP address is part of the relevant subnet associated with a temporary share token. This enables an unauthorized user with access to a valid, non-expired temporary URL to enumerate the subnetId parameter, leading to unrestricted access to sensitive IP address records across various sections and subnets. The exposed data may include hostnames, DNS names, MAC addresses, and critical contact fields, potentially revealing sensitive information such as configuration details and credentials.

Affected Version(s)

phpipam 0 < 1.8.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.