Insecure Direct Object Reference in phpMyFAQ Admin API
CVE-2026-35671

8.7HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-35671?

An insecure direct object reference vulnerability exists in the admin API of phpMyFAQ prior to version 4.1.3. This flaw permits authenticated administrators to modify any user's password without appropriate authorization verification. Malicious actors possessing low-privilege admin credentials can exploit this vulnerability to escalate their privileges to SuperAdmin status by altering the userId parameter in the overwrite-password API request. This risk emphasizes the importance of implementing strict validation measures within administrative functions to prevent unauthorized access and privilege escalation.

Affected Version(s)

phpMyFAQ 0 < 4.1.3

phpMyFAQ 4.1.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cyberHunter127
.