{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/pheditor--2.0.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pheditor (\u003c 2.0.8)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","web-application","ghsa","network"],"_cs_type":"advisory","_cs_vendors":["Pheditor"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability (GHSA-f25v-x6vr-962g) exists in Pheditor, a single-admin PHP file editor, affecting all versions prior to 2.0.8. This flaw allows an unauthenticated attacker to completely circumvent the authentication mechanism and gain full administrative control over any Pheditor instance where the default 'admin' password has not yet been changed. The vulnerability specifically lies within the forced password-change flow, which is triggered when Pheditor detects that the stored admin password is still its default value. Attackers can exploit this by sending an HTTP POST request to \u003ccode\u003epheditor.php\u003c/code\u003e that includes an arbitrary non-empty value for the \u003ccode\u003epheditor_password\u003c/code\u003e parameter, along with a desired new password in \u003ccode\u003epheditor_new_password\u003c/code\u003e and \u003ccode\u003epheditor_confirm_password\u003c/code\u003e. The system fails to verify the submitted \u003ccode\u003epheditor_password\u003c/code\u003e against the actual current password, enabling the attacker to force a password change and subsequently obtain an authenticated session. This significantly compromises the security of affected Pheditor installations, as it grants unauthorized individuals the ability to execute arbitrary PHP code and manipulate the server's file system, leading to potential data compromise or system takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a Pheditor instance running a vulnerable version (prior to 2.0.8) via direct access to \u003ccode\u003epheditor.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker confirms the Pheditor instance is configured with the default 'admin' password, which triggers the forced password-change flow upon attempting to log in.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request targeting the \u003ccode\u003epheditor.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe POST request includes a \u003ccode\u003epheditor_password\u003c/code\u003e parameter with any non-empty string value (e.g., \u003ccode\u003epheditor_password=anything\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe request also includes \u003ccode\u003epheditor_new_password\u003c/code\u003e and \u003ccode\u003epheditor_confirm_password\u003c/code\u003e parameters, specifying the attacker's desired new admin password (e.g., \u003ccode\u003epheditor_new_password=attacker123\u0026amp;pheditor_confirm_password=attacker123\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003epheditor.php\u003c/code\u003e script at line 163 identifies that the stored \u003ccode\u003ePASSWORD\u003c/code\u003e constant is still the default 'admin' hash.\u003c/li\u003e\n\u003cli\u003eDue to the vulnerability, the script proceeds to the password change logic without verifying if the attacker's supplied \u003ccode\u003epheditor_password\u003c/code\u003e value actually matches the current password.\u003c/li\u003e\n\u003cli\u003eThe system updates the 'admin' account's password to the value provided by the attacker, granting the attacker a fully authenticated session and complete administrative control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a complete authentication bypass and full administrative compromise of the Pheditor instance. An unauthenticated attacker can arbitrarily change the administrator password and gain an authenticated session, granting them unrestricted access to edit, create, or delete files on the web server. Since Pheditor is a PHP file editor, this access directly translates to arbitrary code execution capabilities, allowing the attacker to inject malicious scripts, deface websites, exfiltrate data, or establish persistent backdoors on the compromised server. The impact extends to any data and systems accessible by the web server process, potentially leading to severe data breaches, system integrity loss, and further network compromise. The vulnerability is especially dangerous because it negates any perceived security from the presence of a login form, as the attacker does not need to know the default password.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch Pheditor instances to version 2.0.8 or later to remediate CVE-2026-XXXX (GHSA-f25v-x6vr-962g).\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for HTTP POST requests to the \u003ccode\u003e/pheditor.php\u003c/code\u003e endpoint that contain parameters related to password changes (\u003ccode\u003epheditor_new_password\u003c/code\u003e, \u003ccode\u003epheditor_confirm_password\u003c/code\u003e) from unusual or unauthenticated sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T21:56:32Z","date_published":"2026-07-24T21:56:32Z","id":"https://feed.craftedsignal.io/briefs/2026-07-pheditor-auth-bypass/","summary":"A critical authentication bypass vulnerability in Pheditor versions prior to 2.0.8 allows an unauthenticated attacker to gain full administrative access by exploiting a flaw in the forced password-change flow, enabling them to set an arbitrary new admin password and obtain an authenticated session without knowing the current one.","title":"Pheditor Authentication Bypass via Unverified Current Password in Forced Password Change","url":"https://feed.craftedsignal.io/briefs/2026-07-pheditor-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Pheditor (\u003c 2.0.8)","version":"https://jsonfeed.org/version/1.1"}