Critical Vulnerability in phpMyFAQ Allows Privilege Escalation
ID: 0b60205a-1cd4-5c03-bf29-2cb82c68b1ab
STIX ID: report--0b60205a-1cd4-5c03-bf29-2cb82c68b1ab
Feed Name: ThreatCluster
Threat Score
CVE-2026-56396 is a high-severity privilege escalation vulnerability in phpMyFAQ versions prior to 4.1.4 that allows authenticated users with edit_user permissions to set the is_superadmin flag via editUser() and updateUserRights, effectively granting SuperAdmin rights; the issue carries a CVSS base score of 8.8, a patch is available in 4.1.4, and administrators are urged to upgrade and audit accounts with edit_user privileges immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
