PT-2026-54050 · Phpmyfaq · Phpmyfaq

·

CVE-2026-57995

·

Published

2026-06-30

·

Updated

2026-08-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.5
Description An issue exists in the updatePermissions function within the GroupController that allows administrators with GROUP EDIT privileges to grant arbitrary rights to groups without verifying if they possess those rights themselves. A delegated administrator can exploit this by assigning high-value permissions to a group they are a member of, thereby inheriting those rights and escalating their privileges to full administrative control.
Recommendations Update to version 4.1.5 or later. As a temporary mitigation, restrict the use of the updatePermissions function in the GroupController for delegated administrators.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57995
GHSA-PG62-F8G4-4WQH

Affected Products

Phpmyfaq