PT-2026-64999 · Phpmyfaq · Phpmyfaq

·

CVE-2026-66398

·

Published

2026-07-27

·

Updated

2026-07-28

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.6
Description A remote code execution issue exists in the configuration API. Authenticated administrators possessing CONFIGURATION EDIT and ATTACHMENT ADD privileges can write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. The process involves uploading a malicious ZIP file as an attachment, directing the updater configuration to the stored path of that file, and extracting it into the application root to execute code as the web server user.
Recommendations Update phpMyFAQ to version 4.1.6 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66398
GHSA-4FV7-8RR6-RF2W

Affected Products

Phpmyfaq