{"id":"CVE-2026-42569","aliases":["GHSA-fv26-4939-62fh"],"url":"https://o3.security/vulnerability/CVE-2026-42569","summary":"phpvms: /importer authorization bypass causing full database wipe","details":"phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6.","published":"2026-05-09T19:21:48.592Z","modified":"2026-08-07T11:50:47.929593108Z","cvss":{"score":9.4,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"nabeel/phpvms","fixedVersion":"7.0.6"}],"fix":{"url":"https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc","label":"phpvms/phpvms@f59ba8e"},"references":[{"type":"WEB","url":"https://github.com/phpvms/phpvms/releases/tag/7.0.6"},{"type":"WEB","url":"https://github.com/phpvms/phpvms/releases/tag/7.0.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42569.json"},{"type":"ADVISORY","url":"https://github.com/phpvms/phpvms/security/advisories/GHSA-fv26-4939-62fh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42569"},{"type":"FIX","url":"https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:47.929593108Z"}}