CVE-2026-67602 is an authentication bypass vulnerability affecting phpIPAM before version 1.8.2. The flaw exists in the REST API authentication path because the object cache keys entries by lookup value alone and does not incorporate the searched column or lookup method into the cache key. As a result, an object cached during an app_id lookup can be incorrectly reused to satisfy a later app_code lookup. This cache key collision allows an unauthenticated attacker to present a numeric database row identifier as though it were a valid API token and obtain successful authentication. Successful exploitation grants full REST API access and permits unauthorized operations against IP address management data. The fix in 1.8.2 updates cache lookup and write logic so cached objects are keyed with an explicit identifier or method, preventing collisions between distinct lookup paths.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository contains an operational remote exploit and a standalone PHP logic PoC for CVE-2026-67602, an authentication bypass affecting phpIPAM REST API applications using ssl_code security before version 1.8.2. The vulnerability is a cache-key collision: resolving /api/<app_id>/ initially caches the API row by its numeric ID, then the token validation lookup for app_code incorrectly retrieves that same cached row when the supplied phpipam-token equals the row ID. Consequently, the application's actual random app_code is not compared. exploit.py is the primary entry point. It accepts a user-supplied base URL, optionally enumerates likely app_id values by distinguishing invalid-app HTTP 400 responses from authentication-related 401/403 responses, then tests numeric tokens from 1 to a configurable maximum. On a HTTP 200 response it reports authentication bypass and can dump sections, subnets, VLANs, and devices as JSON. It supports X-Forwarded-Proto injection for the intentionally non-TLS lab and optional disabled TLS verification for self-signed environments. The code has no shell or command-execution payload; its impact is unauthorized API access and IPAM-data disclosure, bounded by the compromised application's configured permissions. poc_cache_collision.php is a local PHP reproduction using a stubbed database and copied vulnerable/fixed cache logic. It demonstrates that app_id='client' followed by token='2' authenticates on the vulnerable logic but fails on the fixed logic. docker-compose.yml provisions phpIPAM v1.8.1 with MariaDB and exposes it at localhost:8080; it enables trust of X-Forwarded-Proto specifically for ssl_code testing over HTTP. README.md documents setup, exploitation, indicators (numeric phpipam-token values), and upgrading to 1.8.2 or later as remediation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.