Missing Authorization in phpMyFAQ MCP Server Search Tool
CVE-2026-108851

4.8MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108851?

A vulnerability exists in phpMyFAQ versions up to 4.1.10, specifically affecting the MCP server's faq_search tool. This flaw allows authenticated clients to issue search queries without proper user or group permission checks, potentially exposing restricted FAQs. Attackers connected to the MCP server can access full text of FAQs that should only be visible to specific users or groups, raising significant privacy concerns.

Affected Version(s)

phpMyFAQ 4.1.0 <= 4.1.10

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.