MEDIUM 5.3 NVD
CVE-2026-85587
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attack
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
References
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6w97-49h8-58wh
- https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-incorrect-authorization-via-adm
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.