CVE-2026-91768: 
PHP 취약성 분석 및 완화

개요

CVE-2026-91768 is an IPv6 access control bypass vulnerability in PHP-FPM's FastCGI client access check (listen.allowed_clients). The flaw causes the fcgi_is_allowed() function in main/fastcgi.c to compare only the first 12 bytes (96 bits) of a 16-byte IPv6 address instead of the full address, effectively widening every configured ACL entry to a /96 network prefix. It affects PHP-FPM versions prior to 8.2.34, 8.3.35, 8.4.26, and 8.5.11, and was disclosed on September 24, 2026. The CVSS v3.1 base score is 6.5 (Moderate) (GitHub Advisory).

기술적 세부 사항

The root cause is an improper access control check (CWE-284) in fcgi_is_allowed() within main/fastcgi.c, where a hard-coded memcmp length of 12 is used for IPv6 address comparison instead of the required 16 bytes (sizeof(struct in6_addr)). This means any attacker whose IPv6 source address shares the first 96 bits with a legitimately allowed client address will pass the ACL check. The IPv4 branch correctly compares all 4 bytes, and the IN6_IS_ADDR_V4MAPPED branch legitimately uses a 12-byte offset for a different purpose — but that offset was incorrectly reused as the comparison length for plain IPv6 addresses. Allowed addresses are parsed correctly via inet_pton(AF_INET6, ...), so the truncation silently widens every configured entry to a /96 prefix without any visible configuration error. A proof-of-concept was confirmed against a real php-fpm instance: configuring listen.allowed_clients = ::2 and connecting from ::1 (which shares the first 96 bits) results in the connection being accepted and the PHP script executing (GitHub Advisory).

영향

Successful exploitation allows an attacker with network adjacency to bypass the listen.allowed_clients ACL and reach the FastCGI endpoint, which in typical deployments means the ability to execute arbitrary PHP scripts in the FPM worker context. The primary impact is a high confidentiality risk, as unauthorized script execution can expose sensitive application data, configuration files, or environment variables. Integrity and availability are not directly impacted by the bypass itself. Deployments using Unix domain sockets, IPv4-only configurations, or an external firewall as the primary network boundary are not affected (GitHub Advisory).

악용 가능성

A working proof-of-concept has been confirmed by the reporter against a real php-fpm instance, demonstrating that an attacker sourcing traffic from an IPv6 address sharing the first 96 bits with an allowed client can bypass the ACL. The CVE status is currently "Reserved" with limited public details, and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. No EPSS score or CISA KEV catalog entry has been reported. The attack vector is Adjacent Network with no privileges or user interaction required (GitHub Advisory, Feedly).

착취 단계

  1. Reconnaissance: Identify a target server running PHP-FPM with FastCGI exposed over an IPv6 TCP socket (e.g., listen = [::1]:9000) and listen.allowed_clients configured with one or more IPv6 addresses.
  2. Determine allowed client prefix: Identify or guess an IPv6 address listed in listen.allowed_clients (e.g., ::2). Extract its first 96 bits (first 12 bytes), which is the effective ACL boundary due to the bug.
  3. Craft a source address: Obtain or spoof an IPv6 source address that shares the first 96 bits with the allowed address (e.g., ::1 shares the first 96 bits with ::2 since both are in the ::0/96 prefix).
  4. Send a FastCGI request: Using a FastCGI client tool (e.g., cgi-fcgi, fcgi-client, or a custom script), connect to the PHP-FPM listening socket from the crafted source address and send a valid FastCGI request specifying a target PHP script via SCRIPT_FILENAME.
  5. Achieve script execution: The partial memcmp passes the ACL check, and PHP-FPM executes the requested script in the FPM worker context, returning the output to the attacker (GitHub Advisory).

타협의 징후

  • Network: Unexpected FastCGI connections to PHP-FPM listening ports (default 9000) originating from IPv6 addresses not explicitly listed in listen.allowed_clients but sharing the same /96 prefix; unusual traffic patterns on FastCGI ports from non-web-server source addresses.
  • Logs: PHP-FPM access logs (/var/log/php-fpm/access.log) showing script execution requests from unexpected IPv6 source addresses; FPM error logs showing connections from addresses outside the expected allowed set.
  • Process: PHP-FPM worker processes executing scripts not triggered by the legitimate web server (e.g., nginx or Apache), particularly scripts that access sensitive files or spawn child processes.

완화 및 해결 방법

PHP has released patched versions that fix the comparison to use sizeof(client_sa.sa_inet6.sin6_addr) (all 16 bytes): 8.2.34, 8.3.35, 8.4.26, and 8.5.11. Upgrading to one of these versions is the recommended remediation. As a workaround for environments that cannot immediately upgrade, administrators should restrict FastCGI access using an external firewall or network-level controls rather than relying solely on listen.allowed_clients, or switch to Unix domain sockets which are not affected by this vulnerability (GitHub Advisory, PHP 8.4.26 NEWS).

커뮤니티 반응

The vulnerability was published by the PHP security team (bukka) on September 24, 2026, with fix credit to Alexandre Daubois (developer) and reporters iluuu1994 and iliaal. The Remi repository blog noted the patched releases for RHEL and Fedora shortly after disclosure. Security news outlet SecurityOnline.info covered the PHP vulnerability patch batch. Community discussion has been limited given the "Reserved" CVE status and moderate severity rating (Remi's Blog, SecurityOnline).

추가 자료

리눅스 배포판 수정 현황

주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.

Debian

영향을 받은 사람들

bookworm

php8.2

영향을 받은 사람들

sid

php8.4

영향을 받은 사람들

trixie

php8.4: 8.4.26-1~deb13u1

수정됨

Ubuntu

알 수 없음

bionic (esm-infra)

php7.2

알 수 없음

devel

php8.5

알 수 없음

focal (esm-infra)

php7.4

알 수 없음

jammy

php8.1

알 수 없음

noble

php8.3

알 수 없음

resolute

php8.5

알 수 없음

trusty (esm-infra-legacy)

php5

알 수 없음

xenial (esm-infra-legacy)

php7.0

알 수 없음

RHEL / CentOS

영향을 받은 사람들

RHEL 8

php:7.4/php.src

영향을 받은 사람들

RHEL 9

php.src

영향을 받은 사람들

RHEL 10

php.src

영향을 받은 사람들

Alpine

수정됨

edge

php83: 8.3.35-r0, 8.4.26-r0, 8.5.11-r0

수정됨

근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 PHP 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-91768MEDIUM6.5
  • PHP logoPHP
  • php:7.4::php-common
아니요예Sep 25, 2026
CVE-2026-91767MEDIUM6.5
  • PHP logoPHP
  • php-opcache
아니요예Sep 25, 2026
CVE-2026-92842MEDIUM5.9
  • PHP logoPHP
  • php:8.2::php-process
아니요예Sep 25, 2026
CVE-2026-91766MEDIUM5.9
  • PHP logoPHP
  • php8.4-fpm
아니요예Sep 25, 2026
CVE-2026-91769MEDIUM4.3
  • PHP logoPHP
  • php-fpm
아니요예Sep 25, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자