Skip to content
CVE-2026-104991: High-Risk API Vulnerability in Phproject

CVE-2026-104991: High-Risk API Vulnerability in Phproject

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2026-104991 allows unauthorized access via API keys.
  • •Affected systems are Phproject versions before 1.8.7.
  • •No active exploitation or PoC code reported as of now.

CVE-2026-104991, published on October 2, 2026, identifies a missing object-level authorization vulnerability in Phproject versions prior to 1.8.7. This flaw allows authenticated API key holders to bypass security controls, enabling unauthorized access to restricted issue contents and the ability to post unauthorized comments. Organizations with internet-accessible instances are particularly at risk, especially those with broadly distributed or long-lived API keys. The vulnerability has a CVSS score of 7.1, indicating a high risk, but there is currently no confirmed active exploitation or proof-of-concept code available. Administrators are advised to review API logs and restrict access until a patch is applied. The vendor has not yet confirmed the urgency of this issue, and no exploitation status has been reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
CVE-2026-104991 published
The vulnerability was officially disclosed with a CVSS score of 7.1, categorized as high risk.
www.vulncheck.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-104991 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Phproject versions prior to 1.8.7 are affected by this vulnerability.
Is there a patch available?
The vendor has released a fixed version, 1.8.7, which should be applied to mitigate the risk.
What immediate actions should I take?
Review API logs for unusual access patterns and restrict API access until the patch is applied.