Sceawere
Vulnerability Detail
CVE-2026-108905UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
pH7Builder Hard-Coded API Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- ph7software
- Product
- ph7builder
- Attack Type
- Use of Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-11T15:16:56.803Z",
"pubdate": "2026-10-11T15:16:56.803Z",
"executiveSummary": "pH7Builder versions prior to 18.6.0 contain a critical authentication bypass vulnerability originating from the use of a hard-coded API key. The vulnerability exists within the application's internal API access control logic, specifically residing in Tool.class.php. By leveraging this static credential alongside HTTP Host header manipulation, unauthenticated remote attackers can circumvent existing security checkpoints designed to protect sensitive user data. The impact of this flaw is severe, allowing unauthorized access to personally identifiable information (PII) including registered member email addresses, IP addresses, phone numbers, and financial banking account details. This vulnerability poses a significant risk to user privacy and platform integrity, as it permits full unauthorized data extraction without requiring legitimate administrative or user credentials. The flaw represents a failure in secure credential management and input validation, where the system implicitly trusts the Host header to determine the legitimacy of an API request. Given the sensitive nature of the exposed data, this vulnerability is classified as high-risk, necessitating immediate remediation to prevent widespread data harvesting and privacy breaches.",
"technicalDetails": "The vulnerability is rooted in the improper implementation of API security controls within the Tool.class.php file of the pH7 Social Dating CMS. The application relies on a hard-coded API key, identified as 'dev772277', which is intended for development or internal debugging purposes but remains active in production environments. The authentication logic fails to enforce robust identity verification, instead relying on a weak check that validates the incoming request against an expected URL and the presence of the hard-coded API key.\nThe exploitation process centers on a Host header injection technique. An attacker can initiate an HTTP request to the target server while manually defining the 'Host' header as 'localhost'. By combining this header manipulation with the inclusion of the 'private_api_key=dev772277' parameter in the request string, the attacker triggers a logic flaw in the application's internal API handler. Because the application explicitly trusts requests originating from 'localhost', the server bypasses standard access control checks that would typically restrict sensitive data access to authorized entities or authenticated sessions.\nOnce the Host header is spoofed and the hard-coded key is provided, the application treats the unauthenticated request as a trusted internal call. This permits the attacker to interact with the API endpoints designed for back-end data retrieval. The attack flow is as follows: 1) The attacker identifies a target installation of pH7Builder below version 18.6.0. 2) The attacker crafts an HTTP request, injecting 'Host: localhost' into the request headers. 3) The attacker appends the known hard-coded key 'private_api_key=dev772277' to the request URI. 4) The server-side code in Tool.class.php processes the request, validates the spoofed Host header and the hard-coded key, and returns the requested sensitive datasets.\nThe scope of data exposure is extensive. Successful exploitation grants the attacker read access to the database tables associated with user profiles, exposing PII such as email addresses, physical or network IP addresses, phone numbers, and sensitive banking information. The vulnerability does not require any prior authentication or specific privilege level, making it exploitable by any remote actor with network reach to the web server. This failure represents an intersection of poor secret management and insecure server-side request processing, where trust is derived from mutable HTTP headers rather than cryptographically secure authentication tokens or server-side IP allowlisting."
}