phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.
References
Configurations
No configuration.
History
21 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-21 14:16
Updated : 2026-06-22 18:41
NVD link : CVE-2026-56396
Mitre link : CVE-2026-56396
CVE.ORG link : CVE-2026-56396
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
