Junglewise Threat Intelligence

CVE-2026-12194: phpIPAM authenticated local file inclusion in API

CVE-2026-12194 · Severity: info · CVSS 2.3 · Published 2026-07-04

Technologies: Phpipam. Vendors: Phpipam.

Executive brief

phpIPAM, an open-source IP address management tool, contains a security flaw in its API component. If the API is enabled, an authenticated user can trick the system into loading and executing unintended PHP files from the server's storage. While the API is disabled by default and requires valid credentials to exploit, a successful attack could allow an intruder to run unauthorized code on the server.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the phpIPAM API due to improper sanitization of user-supplied input used to determine controller names. Specifically, the controller name is taken from the request and directly concatenated into a 'require_once' statement without adequate validation (CWE-98). An attacker with a valid API token can exploit this to include and execute any .php file on the web server's filesystem. The vulnerability is only exploitable if the API is manually enabled, as it is disabled by default. A pull request (#4625) has been submitted to address the issue by sanitizing the controller name.

Affected products

  • phpIPAM phpIPAM All versions prior to patch 4625

Timeline

  • 2026-05-28: other: Vulnerability reported to maintainers
  • 2026-07-04: disclosed: Public disclosure via blog post and CVE assignment
  • 2026-07-04: patched: Pull request 4625 submitted to fix the issue

References

Related threats