{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/phproject/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phproject:phproject:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-104991"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Phproject (\u003c 1.8.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Phproject"],"content_html":"\u003cp\u003ePhproject versions prior to 1.8.7 are susceptible to a missing object-level authorization vulnerability within the REST API. Specifically, the endpoints identified as single_get, single_comments, and single_comments_post fail to invoke the necessary allowAccess() authorization routine. This flaw permits an attacker in possession of a valid API key to circumvent the security.restrict_access confidentiality control. By exploiting this oversight, an attacker can access sensitive information, such as issue contents and author email addresses, to which they are not authorized. Furthermore, the vulnerability allows for the unauthorized submission of comments to restricted issues. This impacts the integrity and confidentiality of project data stored within the Phproject instance. Defenders should verify the version of their Phproject deployment and upgrade to 1.8.7 or later to remediate this authorization defect.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to access restricted project data and modify issue comments, potentially leading to unauthorized data exfiltration or manipulation of project records. The severity is assessed as high due to the potential for unauthorized access to sensitive user metadata and internal project communications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Phproject to version 1.8.7 or later immediately to resolve the missing authorization logic in the REST API.\u003c/li\u003e\n\u003cli\u003eReview access logs for the identified REST API endpoints (single_get, single_comments, single_comments_post) to identify abnormal patterns or excessive unauthorized requests by API keys.\u003c/li\u003e\n\u003cli\u003eAudit all active API keys and rotate any keys that show evidence of anomalous usage patterns associated with these endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T20:27:07Z","date_published":"2026-10-02T20:27:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-phproject-auth-bypass/","summary":"Phproject versions before 1.8.7 contain a missing object-level authorization vulnerability in REST API issue endpoints that allows authenticated attackers to bypass security restrictions.","title":"Phproject REST API Authorization Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-phproject-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Phproject","version":"https://jsonfeed.org/version/1.1"}