CVE-2026-12194

Summary

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

Affected Software

VendorProductVersion RangeStatus
phpipamphpipam0 < *affected

Weaknesses

  • CWE-98: CWE-98 Improper control of filename for Include/Require statement in PHP program ('PHP remote file inclusion')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References