phpIPAM released version 1.8.2 to fix a REST API authentication bypass tracked as CVE-2026-67602, caused by an object-cache key collision in versions prior to 1.8.2. According to the vendor patch and advisory, the cache logic keyed entries only by lookup value and not by the searched column, allowing an app_id lookup to collide with an app_code lookup. An unauthenticated attacker could exploit that behavior by supplying a numeric database row identifier as an API token and obtain full API access.
The flaw could allow attackers to read, modify, and delete IP address management records through the API. The security fix updates cache read and write handling across multiple classes so entries are keyed with an explicit identifier and method, preventing collisions between different object lookup paths. The 1.8.2 release also bundles additional security fixes affecting API and sharing functionality, including permission bypasses, arbitrary local file inclusion, insecure direct object references, missing CSRF protections, and second-order SQL injection, alongside signed release artifacts and published SHA-256 hashes.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 24, 2026, VulnCheck published an advisory describing how phpIPAM versions before 1.8.2 could be exploited through insecure REST API object cache keying. The advisory said an unauthenticated attacker could use a numeric database row identifier as an API token to gain full API access and read, write, or delete IP address management records.
On August 16, 2026, phpIPAM released version 1.8.2, which included the fix for the API authentication bypass caused by an object cache key collision. The release also bundled multiple other security fixes affecting API and sharing functionality.
On August 16, 2026, phpIPAM committed a security fix for CVE-2026-67602, an API authentication bypass caused by an object cache key collision. The patch changed cache lookup and write logic to include an explicit identifier and method in cache keys, preventing collisions across different object lookup paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.