---
id: CVE-2026-12194
title: >-
  PHPIPAM is affected by an authenticated local file inclusion vulnerability
  that allows users with access to the API to execute/include arbitrary PHP
  files on the web server's file system
summary: >-
  PHPIPAM is affected by an authenticated local file inclusion vulnerability
  that allows users with access to the API to execute/include arbitrary PHP
  files on the web server's file system. The API is not enabled by default on
  installations.
severity: none
cwe:
  - CWE-98
published: '2026-07-04'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12194'
references:
  - url: 'https://github.com/phpipam/phpipam/pull/4625'
    label: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
  - url: >-
      https://projectblack.io/blog/local-ai-for-cyber-security/#the-benchmark-vulnerabilityphpipam-authenticated-lfi
    label: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
tags:
  - nvd
epss: 0.00378
epssPercentile: 0.29061
ingestedAt: '2026-07-04T21:57:46.867Z'
---

## Overview

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
