CVE-2026-97818: High severity Phpipam Phpipam vulnerability
Published Sep 25, 2026
·Updated
phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
Affected Software
1 affected component
Phpipam Phpipam<=1.8.3
Event History
Sep 25, 2026
CVE Published
via MITRE·04:44 AM
Data Sourced
via MITRE·04:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires no privileges, no user interaction, and has low attack complexity. The impact is confined to systems running phpIPAM through 1.8.3.
2
What is the expected impact of successful exploitation?
The vulnerability has high confidentiality impact and a changed scope rating. The supplied CVSS vector indicates no integrity or availability impact.
3
Which authorization logic is affected?
The issue is in api/controllers/User.php and involves incorrect authorization handling for the id values "admins" and "all".