Posts tagged

Cache-Key-Collision
← Back to all posts
HB

The Token Was a Row Number: CVE-2026-67602 — phpIPAM REST API Authentication Bypass via Cache-Key Collision

On August 24, 2026, VulnCheck’s CNA published CVE-2026-67602, an unauthenticated authentication bypass in the REST API of phpIPAM, the open-source IP address management platform used by network teams to document subnets, addresses, VLANs, devices and circuits. NVD scores i…