Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access. | |
| Title | phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages | |
| First Time appeared |
Phpipam
Phpipam phpipam |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phpipam
Phpipam phpipam |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:31.281Z
Reserved: 2026-10-11T01:52:28.087Z
Link: CVE-2026-108720
No data.
Status : Deferred
Published: 2026-10-11T13:17:15.307
Modified: 2026-10-11T13:17:15.427
Link: CVE-2026-108720
No data.
OpenCVE Enrichment
Updated: 2026-10-11T14:15:17Z
