CVE-2026-107637 | pH7Software pH7Builder up to 18.4.x Note delete id improper authorization
A vulnerability marked as problematic has been reported in pH7Software pH7Builder up to 18.4.x. Affected is the function delete of the component Note Module. This manipulation of the argument ID causes improper authorization.
This vulnerability is tracked as CVE-2026-107637. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More