peter bassill · operator
$ cve CVE-2026-55584 JSON

CVE-2026-55584 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these headers to impersonate a trusted client and access exposed hostname, kernel, CPU, memory, filesystem, and network-interface information. This issue is fixed in version 3.4.6.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS1.91% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-290
On CISA KEVno
Public exploityes
Published2026-08-28
Last modified2026-09-09

Public exploits

SourceTitleDate
exploit-dbphpSysInfo 3.4.5 - IP Allowlist Bypass2026-08-17

References

→ the Explorer  ·  watch your stack  ·  NVD