Description
phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Restricted Data Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in phpIPAM versions through 1.8.3 arises from a missing authorization check in customer, location, and NAT pages. Because Subnets::check_permission is omitted, an authenticated low‑privilege user can request these pages and read IP addresses, CIDRs, hostnames, and MAC addresses that should be restricted. This creates a data‑disclosure flaw (CWE‑862) that allows an attacker to map internal network details without code execution.

Affected Systems

The flaw affects all phpIPAM installations running version 1.8.3 or earlier. The affected product is identified as phpIPAM by the CNA, and the version string is unspecified beyond the threshold, so users should apply any patch later than 1.8.3.

Risk and Exploitability

The CVSS score of 5.3 places it in the medium severity range, and the EPSS score is not reported, implying no known active exploit. The vulnerability requires an authenticated session and is web‑based, so any logged‑in user with basic privileges could exploit it. While it does not compromise system functionality, the exposed network address information can aid attackers in planning further exploits. The vulnerability is not in the CISA KEV catalog, suggesting limited or zero real‑world exploitation to date.

Generated by OpenCVE AI on October 11, 2026 at 13:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade phpIPAM to the latest release that includes the missing authorization check in the customer, location, and NAT pages.
  • If an upgrade is not immediately possible, limit the exposed URLs (customer_objects.php, single-location.php, nat_details.php) to users with appropriate privileges by configuring access controls in the web server or through application‑level filters.
  • Monitor user activity and audit logs for unexpected access to the affected pages and review network discovery logs for newly exposed subnets or host information.

Generated by OpenCVE AI on October 11, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access.
Title phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages
First Time appeared Phpipam
Phpipam phpipam
Weaknesses CWE-862
CPEs cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*
Vendors & Products Phpipam
Phpipam phpipam
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:31.281Z

Reserved: 2026-10-11T01:52:28.087Z

Link: CVE-2026-108720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T13:17:15.307

Modified: 2026-10-11T13:17:15.427

Link: CVE-2026-108720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:17Z

Weaknesses