CVE-2026-42569
phpVMS, a PHP airline simulation application, had a critical flaw that let anyone access a legacy import feature without logging in. This could let attackers upload data or alter the system. The issue was fixed in version 7.0.6.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
phpVMS versions earlier than 7.0.6, used by airline simulation developers and hobbyists.
Real-world impact
An attacker could upload arbitrary data or commands through the import feature, potentially corrupting the database, modifying records, or disrupting service.
Why this severity
The CVSS score of 9.4 reflects that the flaw can be exploited over the network with no authentication or user interaction, and it can severely compromise integrity and availability while only slightly affecting confidentiality.
What to do about it
- 01Upgrade phpVMS to version 7.0.6 or later.
NVD-referenced vendor advisory
Timeline
- May 9, 2026 · May 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 20, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.