Authorization Flaw in phpIPAM Affects User Access Control
CVE-2026-97818

8.6HIGH

Key Information:

Vendor

PHPipam

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-97818?

The phpIPAM version 1.8.3 contains an authorization flaw in the User controller that allows unauthorized access to certain user roles, specifically the 'admins' and 'all' IDs. This vulnerability can lead to unauthorized users gaining access to sensitive user information and permissions that should be restricted, posing a significant risk to the integrity and confidentiality of the user data managed by the application. It is crucial for users to apply necessary patches or updates to mitigate this issue.

Affected Version(s)

phpIPAM 0 <= 1.8.3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.