CVE-2026-75105
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_
CVSS
7.5
High
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Aug 17, 2026 · Last modified: Aug 20, 2026 · CWE-639
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without confirming the address belongs to the authorized subnet. An unauthenticated party holding any valid, non-expired temporary share URL can enumerate the subnetId parameter to read every IP address record across all sections and subnets, including hostnames, DNS names, MAC addresses, owner/contact fields, and notes (which may contain credentials and configuration details).
- github.comhttps://github.com/phpipam/phpipam
- github.comhttps://github.com/phpipam/phpipam/commit/2980be03652c0eb1db9fe2bcefaa210c854b9aea
- github.comhttps://github.com/phpipam/phpipam/issues/4623
- github.comhttps://github.com/phpipam/phpipam/releases/tag/v1.8.2
- www.vulncheck.comhttps://www.vulncheck.com/advisories/phpipam-temporary-subnet-share-information-disclosure-via-address-parameter