{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/phpipam/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75105"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["phpIPAM (1.8.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["phpIPAM"],"content_html":"\u003cp\u003ephpIPAM versions through 1.8.1 contain an authorization vulnerability (CVE-2026-75105) within the temporary share feature. The application fails to verify that a requested IP address belongs to the specific subnet associated with a valid temporary share token. In the files 'app/temp_share/index.php' and 'app/temp_share/address.php', the 'subnetId' parameter is used directly as a database primary key when the share type is set to 'subnets'. This lack of validation allows an unauthenticated user, in possession of any valid, non-expired temporary share URL, to manipulate the 'subnetId' parameter. By iterating through potential IDs, an attacker can enumerate and retrieve IP address records across all sections and subnets. The resulting exposure includes sensitive information such as hostnames, DNS names, MAC addresses, owner details, and potentially notes containing credentials or network configuration details, which poses a significant risk to internal network security.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized access to comprehensive network inventory data. This data can be used by an attacker to perform reconnaissance on internal infrastructure, identify high-value targets, and potentially gain access to credentials stored within IPAM notes. The vulnerability affects all deployments of phpIPAM up to version 1.8.1.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a patched version of phpIPAM that correctly validates subnet ownership for temporary shares.\u003c/li\u003e\n\u003cli\u003eAudit existing temporary shares for abuse or exposure of sensitive notes.\u003c/li\u003e\n\u003cli\u003eImplement access logging to monitor for anomalous traversal of 'subnetId' parameters in the temporary share module.\u003c/li\u003e\n\u003cli\u003eRestrict access to the phpIPAM management interface to trusted internal networks or via VPN to reduce exposure to unauthorized entities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T00:51:38Z","date_published":"2026-08-18T00:51:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-phpipam-auth-bypass/","summary":"phpIPAM versions up to 1.8.1 contain an authorization vulnerability allowing an unauthenticated attacker with a temporary share token to enumerate and exfiltrate sensitive network inventory data.","title":"Authorization Bypass in phpIPAM Temporary Share Feature","url":"https://feed.craftedsignal.io/briefs/2026-08-phpipam-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - PhpIPAM","version":"https://jsonfeed.org/version/1.1"}