phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access. | |
| Title | phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages | |
| First Time appeared |
Phpipam
Phpipam phpipam |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phpipam
Phpipam phpipam |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:31.281Z
Reserved: 2026-10-11T01:52:28.087Z
Link: CVE-2026-108720
No data.
Status : Deferred
Published: 2026-10-11T13:17:15.307
Modified: 2026-10-11T13:17:15.427
Link: CVE-2026-108720
No data.
OpenCVE Enrichment
Updated: 2026-10-11T14:15:17Z
Weaknesses