« Volver al listado

CVE-2026-42569

Estado: AplazadaCrítica (9.4)—

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/AC:L/PR:N/UI:N indica red sin autenticación (T1190). Acceso a feature heredada sin autenticación permite eludir controles de acceso (T1078, CWE-284/862). Potencial modificación de datos de simulación aérea (T1565).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42569",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42569",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-12T13:54:04.519966Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.4,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "phpvms",
          "product": "phpvms",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.0.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-09T20:16:29.127",
  "references": [
    {
      "url": "https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpvms/phpvms/releases/tag/7.0.6",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpvms/phpvms/releases/tag/7.0.7",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/phpvms/phpvms/security/advisories/GHSA-fv26-4939-62fh",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        },
        {
          "lang": "en",
          "value": "CWE-306"
        },
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6."
    },
    {
      "lang": "es",
      "value": "phpVMS es una aplicación PHP para operar y simular una aerolínea. Antes de la versión 7.0.6, una vulnerabilidad crítica en phpVMS permitía el acceso no autenticado a una función de importación heredada. Este problema ha sido parcheado en la versión 7.0.6."
    }
  ],
  "lastModified": "2026-07-20T20:10:00.110",
  "sourceIdentifier": "security-advisories@github.com"
}