Sceawere
Vulnerability Detail
CVE-2026-108720UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
phpIPAM Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- phpipam
- Product
- phpipam
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:15.307Z",
"pubdate": "2026-10-11T13:17:15.307Z",
"executiveSummary": "The vulnerability is identified as a missing authorization flaw within the phpIPAM infrastructure management software.\nAffected versions include phpIPAM through 1.8.3.\nThe flaw allows authenticated low-privileged users to bypass access control lists (ACLs) and view sensitive information within restricted subnets and IP address objects.\nThe impact includes unauthorized disclosure of metadata, including CIDR blocks, hostnames, and MAC addresses, which could facilitate network reconnaissance and further lateral movement.\nExploitation requires an active authenticated session with low-level privileges, as the system fails to enforce standard permission checks on specific backend administrative modules.\nThis vulnerability poses a significant risk to organizations relying on IP address management for network segmentation, as it allows unauthorized users to map internal infrastructure without legitimate authorization.\nThe lack of server-side validation allows an attacker to query objects they are otherwise restricted from accessing through standard UI navigation.",
"technicalDetails": "The root cause of this vulnerability is the improper implementation of access control mechanisms within the backend scripts responsible for rendering customer, location, and NAT details in phpIPAM.\nSpecifically, the application logic fails to invoke the 'Subnets::check_permission' function within 'customer objects.php', 'single-location.php', and 'nat_details.php'.\nIn a secure implementation, phpIPAM relies on this function to verify whether the authenticated user possesses sufficient read/write privileges for the specific subnet or object requested.\nBy omitting this validation step, the application processes requests directly based on object identifiers, regardless of whether the user is authorized to view the data associated with those identifiers.\nThe exploitation flow is straightforward: an authenticated user identifies the URL parameters required to invoke these scripts. By manually crafting requests to these pages—even while authenticated as a low-privilege user—the attacker can bypass the intended permission restrictions.\nThe application acts as a proxy for this sensitive information, exposing details such as IP address allocations, network CIDRs, hostnames, and MAC addresses that are otherwise shielded by the application's RBAC (Role-Based Access Control) framework.\nBecause the application logic trusts the user-supplied object identifiers without re-verifying authorization, an attacker can iterate through object IDs to perform unauthorized reconnaissance of the entire IP inventory, including segments of the network they should not be permitted to view.\nThis bypass effectively renders the security partitioning of the IPAM database void for these specific views.\nThe impact extends beyond mere information disclosure, as the exposure of MAC addresses and hostnames provides critical intelligence for targeted internal attacks, spoofing attempts, or further network mapping.\nThis vulnerability remains exploitable as long as the user maintains a valid session, and no further privileges or complex techniques are required to trigger the failure of the authorization check."
}