PT-2026-85487 · Phpmyfaq · Phpmyfaq

·

CVE-2026-85587

·

Published

2026-08-20

·

Updated

2026-09-04

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.8
Description Incorrect permission checks on admin content pages allow editors with lower privileges to read draft and inactive content. Users with only add permissions can access the 'news edit' and 'FAQ translate' endpoints to view unpublished content that is hidden from the public.
Recommendations Update to version 4.1.8 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14265
CVE-2026-85587
GHSA-6W97-49H8-58WH

Affected Products

Phpmyfaq