{"id":"CVE-2026-42569","aliases":["GHSA-fv26-4939-62fh"],"url":"https://o3.security/vulnerability/CVE-2026-42569","summary":"phpvms: /importer authorization bypass causing full database wipe","details":"# Security Advisory: Unauthenticated Access to Legacy Import Feature\n\n**Severity:** Critical\n**Affected versions:** phpVMS 7.x (up to 7.0.5)\n**Fixed in:** v7.0.6\n**Component:** Legacy importer\n\n## Summary\n\nA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational.\n\n## Impact\n\nA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:\n\n- Data loss\n- Service disruption\n\nNo authentication was required.\n\n## Remediation\n\n- **Update immediately** to [the latest patched version](https://github.com/phpvms/phpvms/releases/tag/7.0.7)\n- If unable to update:\n  - The release link has instructions on how to fix it (it's a one-line fix to comment out the routes)\n\n## Affected Versions\n\n* Affected: phpVMS 7.x ≤ 7.0.5\n* Not affected: phpVMS >= 7.0.6, v8 (feature removed from public access)","published":"2026-05-09T19:21:48.592Z","modified":"2026-08-12T03:51:09.040615663Z","cvss":{"score":9.4,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"},"epss":{"score":0.01173,"percentile":0.64736,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"nabeel/phpvms","fixedVersion":"7.0.6"}],"fix":{"url":"https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc","label":"phpvms/phpvms@f59ba8e"},"references":[{"type":"WEB","url":"https://github.com/phpvms/phpvms/releases/tag/7.0.6"},{"type":"WEB","url":"https://github.com/phpvms/phpvms/releases/tag/7.0.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42569.json"},{"type":"ADVISORY","url":"https://github.com/phpvms/phpvms/security/advisories/GHSA-fv26-4939-62fh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42569"},{"type":"FIX","url":"https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc"},{"type":"PACKAGE","url":"https://github.com/phpvms/phpvms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.040615663Z"}}