
CVE-2026-67602 (9.3 Critical): phpIPAM cached API rows by value, not column — so the app_id lookup answered the app_code check. The integer 1 was a valid API token. The real secret was never compared. Fixed in 1.8.2. #phpIPAM #AppSec https://hunt-benito.com/blog/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass-via-cache-key-collision/ https://t.co/VSVOcduo99
Post summary
The tweet announces a critical authentication bypass in phpIPAM (CVE-2026-67602), details how the cache key collision allows token abuse, notes a patch in version 1.8.2, and links to a blog that likely hosts a PoC.

