logo

Critical Vulnerability in phpMyFAQ Allows Privilege Escalation

ID: 0b60205a-1cd4-5c03-bf29-2cb82c68b1ab

STIX ID: report--0b60205a-1cd4-5c03-bf29-2cb82c68b1ab

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-21

Date Updated: 2026-06-22

...
...

CVE-2026-56396 is a high-severity privilege escalation vulnerability in phpMyFAQ versions prior to 4.1.4 that allows authenticated users with edit_user permissions to set the is_superadmin flag via editUser() and updateUserRights, effectively granting SuperAdmin rights; the issue carries a CVSS base score of 8.8, a patch is available in 4.1.4, and administrators are urged to upgrade and audit accounts with edit_user privileges immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.