CVE-2026-56396
phpMyFAQ
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.
- CVSS
- 8.7
- EPSS
- 0.25% 16.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.21