Phproject REST API Authorization Bypass
Phproject versions before 1.8.7 contain a missing object-level authorization vulnerability in REST API issue endpoints that allows authenticated attackers to bypass security restrictions.
CVE search metadata
CVE search record: CVE-2026-104991. Severity: high. CVSS: 7.1. KEV: no. Product: Phproject (< 1.8.7). Brief: Phproject REST API Authorization Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-10-phproject-auth-bypass/
Phproject versions prior to 1.8.7 are susceptible to a missing object-level authorization vulnerability within the REST API. Specifically, the endpoints identified as single_get, single_comments, and single_comments_post fail to invoke the necessary allowAccess() authorization routine. This flaw permits an attacker in possession of a valid API key to circumvent the security.restrict_access confidentiality control. By exploiting this oversight, an attacker can access sensitive information, such as issue contents and author email addresses, to which they are not authorized. Furthermore, the vulnerability allows for the unauthorized submission of comments to restricted issues. This impacts the integrity and confidentiality of project data stored within the Phproject instance. Defenders should verify the version of their Phproject deployment and upgrade to 1.8.7 or later to remediate this authorization defect.
Impact
Successful exploitation allows authenticated users to access restricted project data and modify issue comments, potentially leading to unauthorized data exfiltration or manipulation of project records. The severity is assessed as high due to the potential for unauthorized access to sensitive user metadata and internal project communications.
Recommendation
- Patch Phproject to version 1.8.7 or later immediately to resolve the missing authorization logic in the REST API.
- Review access logs for the identified REST API endpoints (single_get, single_comments, single_comments_post) to identify abnormal patterns or excessive unauthorized requests by API keys.
- Audit all active API keys and rotate any keys that show evidence of anomalous usage patterns associated with these endpoints.
Mitigations
Upgrade Phproject to 1.8.7 or later
CVE-2026-104991