MEDIUM 6.9 NVD
CVE-2026-75919
phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and cr
phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives.
References
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-f96w-7fx2-79c8
- https://www.vulncheck.com/advisories/phpmyfaq-before-authentication-bypass-via-setup-api
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-f96w-7fx2-79c8
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-19 via NVD.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.