PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107637 ph7software CVE debrief

PatchSiren debrief for CVE-2026-107637: pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action. This medium-severity vulnerability allows authenticated members to delete other members' note comments and categories. System administrators and security teams should assess exposure and verify authentication and authorization controls. The vulnerability is in the note module delete() action, enabling unauthorized deletion of note comments and categories by submitting another member's note ID in the POST id parameter. Affected deployments should review official advisories, plan updates through change control, and verify compensating controls.

Vendor
ph7software
Product
ph7builder
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

System administrators and security teams responsible for pH7Builder installations should assess exposure and verify authentication and authorization controls. They should review official advisories, plan vendor-supported updates or mitigations through normal change control, and monitor for unauthorized deletion of note comments and categories. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is

Why it matters

CVE-2026-107637 is a medium-severity vulnerability in pH7Builder before 18.5.0 that allows authenticated members to delete other members' note comments and categories due to improper authorization. System administrators and security teams should assess exposure, verify authentication and authorization controls, and update to version 18.5.0 or later.

  • Potential unauthorized deletion of note comments and categories
  • Possible data integrity issues due to improper authorization
  • Need for verification of authentication and authorization controls
  • Potential impact on system security due to medium CVSS score

Technical summary

The pH7Builder before 18.5.0 contains an improper authorization vulnerability in the note module delete() action. This allows authenticated members to delete other members' note comments and categories by submitting another member's note ID in the POST id parameter. The vulnerability enables unauthorized deletion of note comments and categories, potentially leading to data integrity issues. System administrators and security teams should assess exposure, verify authentication and authorization controls, and update to version 18.5.0 or later.

Defensive priority

Medium priority for authentication and authorization control verification

Recommended defensive actions

  • Verify authentication and authorization controls for note module delete actions
  • Restrict access to note module delete actions to authorized users
  • Monitor for unauthorized deletion of note comments and categories
  • Update to pH7Builder version 18.5.0 or later
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the improper authorization vulnerability in pH7Builder before 18.5.0. The vulnerability allows authenticated members to delete other members' note comments and categories.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107637 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107637

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107637 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107637

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107637.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/e784139b2385ef44d08a1d586c365857dd777ef6

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.4.1/_protected/app/system/modules/note/controllers/MainController.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pH7Software/pH7-Social-Dating-CMS

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/ph7builder-before-18.5.0-improper-authorization-via-note-module-delete-action

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.