{"id":"GHSA-fv26-4939-62fh","summary":"phpVMS has an /importer authorization bypass causing full database wipe","details":"# Security Advisory: Unauthenticated Access to Legacy Import Feature\n\n**Severity:** Critical\n**Affected versions:** phpVMS 7.x (up to 7.0.5)\n**Fixed in:** v7.0.6\n**Component:** Legacy importer\n\n## Summary\n\nA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational.\n\n## Impact\n\nA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:\n\n- Data loss\n- Service disruption\n\nNo authentication was required.\n\n## Remediation\n\n- **Update immediately** to [the latest patched version](https://github.com/phpvms/phpvms/releases/tag/7.0.7)\n- If unable to update:\n  - The release link has instructions on how to fix it (it's a one-line fix to comment out the routes)\n\n## Affected Versions\n\n* Affected: phpVMS 7.x ≤ 7.0.5\n* Not affected: phpVMS \u003e= 7.0.6, v8 (feature removed from public access)","aliases":["CVE-2026-42569"],"modified":"2026-05-13T13:54:44.258293Z","published":"2026-05-04T21:20:40Z","database_specific":{"cwe_ids":["CWE-284","CWE-306","CWE-862"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-04T21:20:40Z","nvd_published_at":"2026-05-09T20:16:29Z"},"references":[{"type":"WEB","url":"https://github.com/phpvms/phpvms/security/advisories/GHSA-fv26-4939-62fh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42569"},{"type":"WEB","url":"https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc"},{"type":"PACKAGE","url":"https://github.com/phpvms/phpvms"},{"type":"WEB","url":"https://github.com/phpvms/phpvms/releases/tag/7.0.6"},{"type":"WEB","url":"https://github.com/phpvms/phpvms/releases/tag/7.0.7"}],"affected":[{"package":{"name":"nabeel/phpvms","ecosystem":"Packagist","purl":"pkg:composer/nabeel/phpvms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.6"}]}],"versions":["7.0.0","7.0.0-beta.2","7.0.0-beta.3","7.0.0-beta.4","7.0.0-beta.5","7.0.1","7.0.2","7.0.3","7.0.4","7.0.5","v7.0.0-alpha2","v7.0.0-beta"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fv26-4939-62fh/GHSA-fv26-4939-62fh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"}]}