Improper Comparison Vulnerability in olivier-ls PHP-FTS Component
CVE-2026-93957

5.3MEDIUM

Key Information:

Vendor

Olivier-ls

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-93957?

An improper comparison vulnerability exists in the olivier-ls PHP-FTS component, specifically in the function SearchEngine::matchesSingleFilter located in src/SearchEngine.php. This can lead to unexpected behavior due to incorrect filter matching, allowing remote attackers to exploit the system. A publicly disclosed exploit could be used against vulnerable systems running versions up to 1.1.3. Users are urged to upgrade to version 1.1.4 or later to address this issue. The vendor promptly released a patch, identified by commit 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3, demonstrating a commitment to maintaining security.

Affected Version(s)

PHP-FTS 1.1.0

PHP-FTS 1.1.1

PHP-FTS 1.1.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

summmm (VulDB User)
VulDB CNA Team
.