PT-2026-103631 · Unknown · Simple-Php-Router

·

CVE-2026-103592

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions simple-php-router versions prior to 5.4.1.8
Description The IpRestrictAccess middleware contains a flaw that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. By spoofing the X-Forwarded-For, CF-Connecting-IP, or Client-IP headers, an attacker can impersonate whitelisted addresses or evade blacklists to gain unauthorized access to IP-restricted routes.
Recommendations Update simple-php-router to version 5.4.1.8 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103592

Affected Products

Simple-Php-Router