CVE-2026-108905
pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields.
| CWE | CWE-798 |
| Vendor | ph7software |
| Product | ph7builder |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for ph7software ph7builder
Be the first to know when new high vulnerabilities affecting ph7software ph7builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
ph7software / ph7builder
0 < 18.6.0
References
github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/cfe1e0c418946b868db8c399d0cf6b122552efd2 github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.5.1/_protected/framework/Api/Tool.class.php#L25-L48 github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS vulncheck.com: https://www.vulncheck.com/advisories/ph7builder-before-18.6.0-hard-coded-api-key-bypass-via-host-header
Credits
Haluk Baran AKBULUT (CyberMap Group)