CVE-2026-12194: PHPIPAM Authenticated LFI
Published Jul 4, 2026
·Updated
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.
Affected Software
1 affected component
Phpipam Phpipam
Event History
Jul 4, 2026
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12194?
The severity of CVE-2026-12194 is rated as low with a CVSS score of 4.0.
2
How do I fix CVE-2026-12194?
To mitigate CVE-2026-12194, ensure the API is disabled if not needed and regularly update PHPIPAM to the latest version.
3
What does CVE-2026-12194 affect?
CVE-2026-12194 affects the PHPIPAM application allowing authenticated users to exploit local file inclusion vulnerabilities.
4
Is the API enabled by default in PHPIPAM for CVE-2026-12194?
No, the API is not enabled by default in PHPIPAM installations.
5
What type of vulnerability is CVE-2026-12194?
CVE-2026-12194 is an authenticated local file inclusion vulnerability.