Junglewise Threat Intelligence

CVE-2026-42569: phpVMS authentication bypass in legacy importer

CVE-2026-42569 · Severity: critical · CVSS 9.4 · Published 2026-05-09

Vendors: Packagist.

Executive brief

phpVMS is an application used to manage and simulate virtual airline operations. A security flaw in the software's legacy data import tool allows unauthorized individuals to access sensitive administrative functions without a password. An attacker could use this access to delete the entire database or modify critical flight and user data, leading to a total loss of service and operational data.

Technical details

A critical vulnerability exists in phpVMS due to missing authentication and authorization checks (CWE-306, CWE-862) in the legacy importer component. The application fails to restrict access to the '/importer' routes, allowing any remote, unauthenticated attacker to trigger internal data processing routines. Exploitation can lead to a full database wipe or unauthorized modification of application state. The issue was addressed in version 7.0.6 by removing the web-facing importer routes entirely. A manual mitigation is available by removing or commenting out the 'mapImporterRoutes()' call in the RouteServiceProvider.

Affected products

  • phpVMS phpVMS < 7.0.6

Timeline

  • 2026-04-23: patched: Version 7.0.6 released to address the vulnerability.
  • 2026-04-23: advisory: GitHub Security Advisory GHSA-fv26-4939-62fh published.
  • 2026-05-09: disclosed: CVE-2026-42569 published to the NVD.

References