PT-2026-36989 · Phpvms · Phpvms

Peter-Bosch

·

Published

2026-05-04

·

Updated

2026-05-12

·

CVE-2026-42569

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpVMS versions 7.x through 7.0.5
Description A critical issue in the legacy importer component allows unauthenticated access to a deprecated import feature. A remote attacker can trigger internal processes to modify or delete application data, which may lead to data loss or service disruption.
Recommendations Update to version 7.0.6 or later. As a temporary workaround, comment out the routes associated with the legacy importer to disable access to the feature.

Fix

Missing Authorization

Missing Authentication

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-42569
GHSA-FV26-4939-62FH

Affected Products

Phpvms