{"id":"CVE-2026-104991","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-104991","summary":"Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated…","details":"Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess() authorization routine. Attackers can use a valid API key to read restricted issue contents and comments, including owner and author email addresses, and post unauthorized comments to issues they should not have access to.","published":"2026-10-02T20:17:01.513","modified":"2026-10-02T20:17:01.513","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Alanaktion/phproject/releases/tag/v1.8.7"},{"type":"WEB","url":"https://github.com/Alanaktion/phproject/security/advisories/GHSA-mpq9-v47x-3hw8"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/phproject-missing-authorization-via-issues-rest-api"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T20:17:01.513"}}