PatchSiren cyber security CVE debrief
CVE-2026-107637 ph7software CVE debrief
PatchSiren debrief for CVE-2026-107637: pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action. This medium-severity vulnerability allows authenticated members to delete other members' note comments and categories. System administrators and security teams should assess exposure and verify authentication and authorization controls. The vulnerability is in the note module delete() action, enabling unauthorized deletion of note comments and categories by submitting another member's note ID in the POST id parameter. Affected deployments should review official advisories, plan updates through change control, and verify compensating controls.
- Vendor
- ph7software
- Product
- ph7builder
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
System administrators and security teams responsible for pH7Builder installations should assess exposure and verify authentication and authorization controls. They should review official advisories, plan vendor-supported updates or mitigations through normal change control, and monitor for unauthorized deletion of note comments and categories. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is
Why it matters
CVE-2026-107637 is a medium-severity vulnerability in pH7Builder before 18.5.0 that allows authenticated members to delete other members' note comments and categories due to improper authorization. System administrators and security teams should assess exposure, verify authentication and authorization controls, and update to version 18.5.0 or later.
- Potential unauthorized deletion of note comments and categories
- Possible data integrity issues due to improper authorization
- Need for verification of authentication and authorization controls
- Potential impact on system security due to medium CVSS score
Technical summary
The pH7Builder before 18.5.0 contains an improper authorization vulnerability in the note module delete() action. This allows authenticated members to delete other members' note comments and categories by submitting another member's note ID in the POST id parameter. The vulnerability enables unauthorized deletion of note comments and categories, potentially leading to data integrity issues. System administrators and security teams should assess exposure, verify authentication and authorization controls, and update to version 18.5.0 or later.
Defensive priority
Medium priority for authentication and authorization control verification
Recommended defensive actions
- Verify authentication and authorization controls for note module delete actions
- Restrict access to note module delete actions to authorized users
- Monitor for unauthorized deletion of note comments and categories
- Update to pH7Builder version 18.5.0 or later
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the improper authorization vulnerability in pH7Builder before 18.5.0. The vulnerability allows authenticated members to delete other members' note comments and categories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107637 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107637
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107637 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107637
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107637.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/e784139b2385ef44d08a1d586c365857dd777ef6
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.4.1/_protected/app/system/modules/note/controllers/MainController.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/pH7Software/pH7-Social-Dating-CMS
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/ph7builder-before-18.5.0-improper-authorization-via-note-module-delete-action
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.