Missing Authorization in phpMyFAQ MCP Server Search Tool
CVE-2026-108851
4.8MEDIUM
What is CVE-2026-108851?
A vulnerability exists in phpMyFAQ versions up to 4.1.10, specifically affecting the MCP server's faq_search tool. This flaw allows authenticated clients to issue search queries without proper user or group permission checks, potentially exposing restricted FAQs. Attackers connected to the MCP server can access full text of FAQs that should only be visible to specific users or groups, raising significant privacy concerns.
Affected Version(s)
phpMyFAQ 4.1.0 <= 4.1.10
