PT-2026-60698 · Git+2 · Pheditor+1
CVE-2026-55579
·
Published
2026-07-16
·
Updated
2026-07-27
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pheditor versions 2.0.1 through 2.0.5
Description
Pheditor contains a hardcoded default password
admin stored as a SHA-512 hash in the pheditor.php file. The application lacks a mechanism to force a password change upon the first login. An attacker using these default credentials can gain full administrative access to the file editor, file upload, and terminal features. This allows for arbitrary file read and write operations, as well as remote code execution. The password change feature writes the new hash directly into the PHP source file, meaning anyone with read access to the source can extract it.Recommendations
Update to version 2.0.6.
As a temporary mitigation, change the default password immediately via the application settings to prevent unauthorized access.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pheditor
Pheditor/Pheditor