---
id: CVE-2026-97818
title: >-
  phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and
  id=="all" in api/controllers/User.php.
summary: >-
  phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and
  id=="all" in api/controllers/User.php.
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: phpipam
product: phpIPAM
affected:
  - phpIPAM <= 1.8.3
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T14:17:26.837'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97818'
references:
  - url: >-
      https://github.com/phpipam/phpipam/blob/e8010751d491e485acefa5787fb0e518eb948771/api/controllers/User.php#L143-L146
    label: cve@mitre.org
  - url: 'https://github.com/phpipam/phpipam/releases/tag/v1.8.3'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-25T13:53:40.833250Z'
epss: 0.00317
epssPercentile: 0.22065
ingestedAt: '2026-09-25T04:59:31.583Z'
---

## Overview

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
