Vulnerability Description
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.
Related Weaknesses (CWE)
References
- https://github.com/phpipam/phpipam/pull/4625
- https://projectblack.io/blog/local-ai-for-cyber-security/#the-benchmark-vulnerab
FAQ
What is CVE-2026-12194?
CVE-2026-12194 is a documented vulnerability. PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is n...
How severe is CVE-2026-12194?
CVSS scoring is not yet available for CVE-2026-12194. Check NVD for updates.
Is there a patch for CVE-2026-12194?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.