PT-2026-98287 · Fastcgi · Fastcgi

·

CVE-2026-91768

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The FastCGI client access check for IPv6 addresses incorrectly compares only the first 12 bytes of a 16-byte address. This causes the listen.allowed clients check to match based on a /96 prefix rather than the exact address. An attacker using an address that shares the first 96 bits with an authorized address can bypass the access control and reach the FastCGI endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91768
OPENSUSE-SU-2026:11901-1

Affected Products

Fastcgi