SecuritylabJuly 23, 2026🇷🇺Translated from Russian

PHP Type Juggling Vulnerabilities: How Loose Comparisons Enable Authentication Bypass in Legacy Applications

PHP has long outgrown its origins as a language for small websites. Banking portals, CRMs, e-commerce platforms, corporate intranets, and APIs now run on it, yet one of its oldest features continues to produce critical vulnerabilities: automatic type coercion known as Type Juggling.

For developers, comparing a string with a number without explicit casting feels convenient. For penetration testers, it offers a reliable way to bypass password checks, HMAC validation, token verification, or authorization logic. That is why PHP Type Juggling challenges appear regularly in CTF competitions, PortSwigger labs, and older real-world applications.

Why Type Juggling Exists

PHP uses dynamic typing. Variables have no fixed type, and the interpreter constantly converts values to the most suitable type. The expression $a = "10"; $b = 10; var_dump($a == $b); returns true because the string is interpreted as the integer 10. Problems arise when non-numeric strings are forced into numeric comparisons, producing unexpected results that can completely alter application logic.

Loose versus Strict Comparison

The operator == performs loose comparison after type coercion, while === checks both type and value. Consequently, "10" === 10 evaluates to false, but "10" == 10 evaluates to true. Using == with passwords, tokens, HMAC values, or cryptographic hashes creates the conditions for Type Juggling attacks.

Most Dangerous Coercions and Magic Hashes

When a string begins with digits, PHP uses only the numeric portion. In older versions, "admin" == 0 and "0admin" == 0 both returned true. The most famous technique involves scientific notation: the string "0e12345" is treated as the number zero. This behavior enables magic hash attacks where two different MD5 hashes starting with 0e followed only by digits compare as equal after coercion to zero.

Array-to-String Substitution and NULL Returns

Attackers can supply ?token[]=123 to force $_GET['token'] into an array. In older PHP versions, functions such as hash_hmac() return NULL and emit a warning when given an array instead of a string. The subsequent loose comparison NULL == "" succeeds, completely bypassing signature validation.

PHP 8 Improvements and Remaining Risks

PHP 8 changed many string-to-number comparisons so that "admin" == 0 now returns false. Nevertheless, large numbers of applications still run on PHP 7.4 and earlier, and new vulnerabilities continue to appear from incorrect handling of NULL values, arrays, and cryptographic results.

Detection and Defense

Testers should look for == or != near calls to md5(), sha1(), hash(), or hash_hmac(), especially in token or cookie validation logic. Defenses include replacing all loose comparisons with ===, using hash_equals() for cryptographic values, explicitly rejecting arrays where strings are expected, and calling in_array($value, $array, true) to enforce strict comparison.

The article concludes with an invitation to practice on the ONE TASK challenge “At Jamshut’s” available after free registration for the White Hacker Profession course, allowing participants to discover and exploit a realistic Type Juggling flaw in a production-like application.

Related articles

HabrVulnerabilities & Exploits

RCE Vulnerability in AI Code Editors Cursor, VS Code and Google Antigravity Threatens 50 Million Developers

Researchers at AISLE discovered a critical remote code execution vulnerability affecting the AI-powered code editors Cursor, Microsoft Visual Studio Code and Google Antigravity. The flaw allowed attackers to achieve RCE simply by tricking a developer into opening a specially crafted link embedded in a Git commit message. Successful exploitation granted full access to API keys, local files, and the ability to install persistent malware without any visible indicators. The issue stemmed from shared architectural components inherited from the Visual Studio Code codebase, which Cursor and Google Antigravity both adopted. All three vendors have released patches, yet the incident highlights systemic supply-chain risks in the rapidly growing AI-IDE ecosystem. Approximately 50 million developers were potentially exposed before fixes were deployed.

HabrVulnerabilities & Exploits

NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU

Neoflex has released NEOMSA APIM 4.6.0 with a primary focus on strengthening the security of the platform's supply chain. The team generated an SBOM in CycloneDX format, scanned components and dependencies using Grype, and cross-referenced findings against the FSTEC BDU database. This process reduced total registered vulnerabilities from 57 to 7, completely removing all 10 Critical and 24 High issues. The platform now meets the formal Security Gate criterion requiring zero Critical or High vulnerabilities from the FSTEC database in the final build. Remaining Medium findings are documented and tracked for future updates. The release provides customers with a verified, transparent component inventory that simplifies compliance and integration reviews.

Security NEXTVulnerabilities & Exploits

Cisco Publishes 12 Security Advisories Fixing Critical Flaws in Catalyst SD-WAN and IOS XE

Cisco Systems released 12 new security advisories on August 5, 2026, disclosing a total of 23 vulnerabilities across multiple products. Two advisories covering Cisco Catalyst SD-WAN Software and Cisco IOS XE Software received the highest Critical severity rating. The SD-WAN advisory addresses five issues, including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring 9.9 on CVSSv3.1. The IOS XE advisory details seven vulnerabilities, with CVE-2026-20272 rated 9.8 and CVE-2026-20267 rated 9.0. Additional advisories cover flaws in Integrated Management Controller, RoomOS, and Terminal Services Agent. Organizations are urged to apply the hardening releases immediately to mitigate remote exploitation risks.

AntiMalwareVulnerabilities & Exploits

Head Mare Hackers Exploit TrueConf Servers to Distribute PhantomCore and PhantomGraph Backdoors

Russian organizations have been targeted in a new campaign by the Head Mare group, which compromises unpatched TrueConf servers to deliver backdoors. Attackers chain vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with maximum privileges on affected servers. They then replace a server file with a web shell to explore the victim's infrastructure, access the TrueConf database, and substitute the client installer. Victims are tricked via social engineering into downloading the malicious client during video conferences without any suspicious emails. The campaign affects TrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. Kaspersky researchers recommend immediate updates to patched versions 5.3.9, 5.4.9, and 5.5.5 released on 18 June 2026. The threat extends beyond direct TrueConf users, as any employee invited to a compromised server can inadvertently install the backdoor.