PT-2026-51237 · Phpmyfaq · Phpmyfaq

·

CVE-2026-56396

·

Published

2026-05-25

·

Updated

2026-06-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.4
Description Missing authorization flaws in the editUser() and updateUserRights() endpoints allow authenticated administrators to escalate privileges. An authenticated non-SuperAdmin user possessing the edit user permission can modify the is superadmin flag or grant arbitrary rights to an account, enabling them to gain full SuperAdmin access and complete control over the knowledge base.
Recommendations Upgrade to version 4.1.4.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08480
CVE-2026-56396
GHSA-985R-Q3QP-299H

Affected Products

Phpmyfaq