CVE-2026-55584
HIGH 7.5EPSS 2.4%
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these headers to impersonate a trusted client and access exposed hostname, kernel, CPU, memory, filesystem, and network-interface information. This issue is fixed in version 3.4.6.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 2.42% chance of exploitation in the next 30 days, 83th percentile
- Published
- 2026-08-28
- Updated
- 2026-08-31
Proof-of-concept exploits (2)
- advisories/GHSA-786w-p5pm-cvgh
- mirackayikci/CVE-2026-555840★ · 2026-06-25