logo

Critical Vulnerability in phpMyFAQ Allows Privilege Escalation

ID: fb97559d-93e5-53d7-bcf1-8d529e0ba9b0

STIX ID: report--fb97559d-93e5-53d7-bcf1-8d529e0ba9b0

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-21

Date Updated: 2026-06-22

...
...

A critical privilege-escalation vulnerability (CVE-2026-56396) impacts phpMyFAQ versions prior to 4.1.4, allowing authenticated users with edit_user permissions to escalate themselves to SuperAdmin by modifying the is_superadmin flag via editUser and updateUserRights endpoints. The issue has a CVSS base score of 8.8; a patch is available in phpMyFAQ 4.1.4 and organizations are urged to upgrade immediately and audit accounts with edit_user privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.