CVE-2026-55584High· 7.5▾ MidnightPoC availablephpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
2.4%
Last analysed / modified upstream
Exploit-DB · 1 GitHub repo (last check)
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these headers to impersonate a trusted client and access exposed hostname, kernel, CPU, memory, filesystem, and network-interface information. This issue is fixed in version 3.4.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
phpsysinfo/phpsysinfo <= 3.4.5Patched in:
phpsysinfo/phpsysinfo 3.4.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62987Medium· 5.8Fabio is an HTTP(S) and TCP router for deploying applications managed by consul
CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2025-68624Medium· 4.3N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants
CVE-2026-86196High· 8.7Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains
CVE-2026-49757CriticalAshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)