Skip to content
Threat Feed

Vendor

Pheditor

4 briefs RSS
critical advisory

Pheditor Authentication Bypass via Unverified Current Password in Forced Password Change

A critical authentication bypass vulnerability in Pheditor versions prior to 2.0.8 allows an unauthenticated attacker to gain full administrative access by exploiting a flaw in the forced password-change flow, enabling them to set an arbitrary new admin password and obtain an authenticated session without knowing the current one.

pheditor authentication-bypass web-application ghsa network
3t
high advisory

Pheditor Terminal Argument Injection Leads to Remote Code Execution

A vulnerability in Pheditor's terminal feature (versions <= 2.0.6) allows authenticated attackers to achieve arbitrary command execution via argument injection into allowlisted binaries, which can be chained with default credentials for effective unauthenticated remote code execution on the underlying host.

Pheditor argument-injection rce web-application cwe-88
4r 2t
critical advisory

Pheditor Hardcoded Admin Password Leads to Remote Code Execution (CVE-2026-55579)

Pheditor contains a critical vulnerability (CVE-2026-55579) where a hardcoded default password 'admin' with no forced change mechanism upon first login allows an unauthenticated attacker to gain full administrative access, enabling arbitrary file read/write and remote code execution through the application's terminal feature, leading to complete server compromise.

Pheditor +1 hardcoded-credentials rce web-application cve web-vulnerability command-injection php
1r 5t
high advisory

Pheditor Authenticated Command Whitelist Bypass via Shell Command Substitution

Pheditor 2.0.4 contains an authenticated command injection vulnerability, CVE-2026-54540, allowing a user with `terminal` permissions to bypass the `TERMINAL_COMMANDS` whitelist by leveraging shell command substitution to execute arbitrary shell commands as the web server user.

Pheditor 2.0.4 web-vulnerability command-injection php
1r 1t