---
id: CVE-2026-93957
title: A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3
summary: >-
  A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects
  the function SearchEngine::matchesSingleFilter of the file
  src/SearchEngine.php of the component Filter Matching. The manipulation leads
  to incorrect comparis…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-697
vendor: olivier-ls
product: PHP-FTS
affected:
  - PHP-FTS 1.1.0
  - PHP-FTS 1.1.1
  - PHP-FTS 1.1.2
  - PHP-FTS 1.1.3
published: '2026-09-20'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T17:17:30.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93957'
references:
  - url: 'https://github.com/olivier-ls/php-fts/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/olivier-ls/php-fts/commit/0b2fae333d6b022da7ed4c43e2d41aa03f91dff3
    label: cna@vuldb.com
  - url: 'https://github.com/olivier-ls/php-fts/issues/2'
    label: cna@vuldb.com
  - url: 'https://github.com/olivier-ls/php-fts/releases/tag/v1.1.4'
    label: cna@vuldb.com
  - url: >-
      https://github.com/sumo166/CVE-apply/blob/main/olivier-ls/PHP-FTS/SearchEngine%20matchesSingleFilter%20Loose%20Comparison%20Filter%20Bypass%20(CWE-697)_cve.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-93957'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/943923'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407916'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407916/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00491
epssPercentile: 0.39611
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T16:03:35.296396Z'
ingestedAt: '2026-09-20T02:12:35.983Z'
---

## Overview

A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. The manipulation leads to incorrect comparison. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.4 is able to mitigate this issue. The identifier of the patch is 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
