CVE-2026-67602Patch

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an app_id lookup to satisfy a subsequent app_code lookup, allowing attackers to use the numeric database row identifier as an API token to read, write, and delete all IP address management records.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-25: 1Mentions · 2026-08-28: 1PoC Mentioned / Linked · 2026-08-28: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-28: 108-2508-28
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-251
Patch1
2026-08-281
Disclosure1
Full discourse2 posts
  • Hunt-Benito@HB_CyberSec
    Disclosure

    CVE-2026-67602 (9.3 Critical): phpIPAM cached API rows by value, not column — so the app_id lookup answered the app_code check. The integer 1 was a valid API token. The real secret was never compared. Fixed in 1.8.2. #phpIPAM #AppSec https://hunt-benito.com/blog/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass-via-cache-key-collision/ https://t.co/VSVOcduo99

    Post summary

    The tweet announces a critical authentication bypass in phpIPAM (CVE-2026-67602), details how the cache key collision allows token abuse, notes a patch in version 1.8.2, and links to a blog that likely hosts a PoC.

    0000042
    4 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    High CVSS 9.3 CVE-2026-67602 in phpIPAM <1.8.2 allows unauthenticated REST API access. Update immediately if deployed. Guidance at https://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/sPRzIMLI9b

    Post summary

    CVE‑2026‑67602 is a high‑severity flaw in phpIPAM versions < 1.8.2 that allows unauthenticated REST API access; users should update immediately.

    0000036
    93 followersView on X

Explore more