CVE-2026-107638
Deferred Deferred - Pending Action

Improper Authentication Bypass in pH7Builder Social Dating CMS

Vulnerability report for CVE-2026-107638, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who know an account password can submit unlimited 6-digit verification codes to VerificationCodeFormProcess.php to take over member, affiliate, or administrator accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ph7software ph7builder 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects pH7Builder (pH7 Social Dating CMS) versions before 18.5.0. It allows attackers to bypass two-factor authentication by submitting unlimited 6-digit TOTP verification codes without rate limiting. Attackers with a valid password can repeatedly guess codes to gain unauthorized access to accounts.

Detection Guidance

Check for repeated failed 2FA attempts in logs for VerificationCodeFormProcess.php. Monitor for multiple 6-digit code submissions from the same IP or account within a short timeframe. Look for successful logins after a high number of failed attempts.

Impact Analysis

If you use pH7Builder before version 18.5.0, an attacker who knows your password could bypass 2FA and take over your account. This could lead to unauthorized access to personal data, account misuse, or further compromise of your system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance penalties if user data is compromised due to this flaw.

Mitigation Strategies

Upgrade pH7Builder to version 18.5.0 or later to apply the rate-limiting fix. If upgrading is not possible, implement IP-based rate limiting for 2FA attempts manually. Review logs for signs of brute-force attempts and block suspicious IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107638. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart