Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #12
Phproject vulnerability lets API users bypass issue restrictions
Original: CVE-2026-104991 is a missing-authorization flaw in Alanaktion Phproject. Authenticated API key holders can bypass restri
A missing-authorization vulnerability, CVE-2026-104991, has been disclosed in Alanaktion Phproject. Authenticated users with API keys can bypass restricted-issue controls to read issue contents, comments and email addresses, and post unauthorized comments. Versions 1.1.6 through 1.8.6 are affected. Security communities are sharing the advisory as administrators assess whether their deployments need patching.
Why now: A newly disclosed CVE in a self-hosted project management tool raises immediate patching concerns for anyone running it.
Alanaktion PhprojectCVE-2026-104991
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1007890