PT-2026-78393 · Phpmyfaq · Phpmyfaq

·

CVE-2026-76211

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.7
Description Insufficient enforcement of the CONFIGURATION EDIT permission on administrative API read endpoints allows any authenticated user to access sensitive administrative data. By utilizing a valid session, an attacker can retrieve information regarding LDAP server topology, bind account names, search bases, index statistics, and site analytics. The affected endpoints relate to the configuration of LDAP, Elasticsearch, OpenSearch, and the dashboard.
Recommendations Update to version 4.1.7 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76211
GHSA-7GH7-QH7C-9R8M

Affected Products

Phpmyfaq