CVE-2026-55579
Pheditor, a PHP-based single-file editor, shipped versions 2.0.1 through 2.0.5 with a hard‑coded default password of "admin". Because there is no forced password change on first login, any installation using these versions can be accessed by anyone who knows the default credentials.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Pheditor versions 2.0.1 to 2.0.5 (any PHP deployment using these releases).
Real-world impact
An attacker who logs in with the default credentials can use the file editor, upload files, and run terminal commands, allowing them to read, modify, or delete any file on the server and execute arbitrary code.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is network‑exposed, requires no attacker privileges or user interaction, and grants complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Pheditor to version 2.0.6 or later, which removes the hard‑coded default password.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.