PT-2026-60698 · Git+2 · Pheditor+1

CVE-2026-55579

·

Published

2026-07-16

·

Updated

2026-07-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pheditor versions 2.0.1 through 2.0.5
Description Pheditor contains a hardcoded default password admin stored as a SHA-512 hash in the pheditor.php file. The application lacks a mechanism to force a password change upon the first login. An attacker using these default credentials can gain full administrative access to the file editor, file upload, and terminal features. This allows for arbitrary file read and write operations, as well as remote code execution. The password change feature writes the new hash directly into the PHP source file, meaning anyone with read access to the source can extract it.
Recommendations Update to version 2.0.6. As a temporary mitigation, change the default password immediately via the application settings to prevent unauthorized access.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55579
GHSA-P4H7-P9RJ-2PQ2

Affected Products

Pheditor
Pheditor/Pheditor