Critical Vulnerability in phpMyFAQ Allows Privilege Escalation
ID: fb97559d-93e5-53d7-bcf1-8d529e0ba9b0
STIX ID: report--fb97559d-93e5-53d7-bcf1-8d529e0ba9b0
Feed Name: ThreatCluster
Threat Score
A critical privilege-escalation vulnerability (CVE-2026-56396) impacts phpMyFAQ versions prior to 4.1.4, allowing authenticated users with edit_user permissions to escalate themselves to SuperAdmin by modifying the is_superadmin flag via editUser and updateUserRights endpoints. The issue has a CVSS base score of 8.8; a patch is available in phpMyFAQ 4.1.4 and organizations are urged to upgrade immediately and audit accounts with edit_user privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
