Insecure Direct Object Reference in phpMyFAQ Admin API
CVE-2026-35671
8.7HIGH
What is CVE-2026-35671?
An insecure direct object reference vulnerability exists in the admin API of phpMyFAQ prior to version 4.1.3. This flaw permits authenticated administrators to modify any user's password without appropriate authorization verification. Malicious actors possessing low-privilege admin credentials can exploit this vulnerability to escalate their privileges to SuperAdmin status by altering the userId parameter in the overwrite-password API request. This risk emphasizes the importance of implementing strict validation measures within administrative functions to prevent unauthorized access and privilege escalation.
Affected Version(s)
phpMyFAQ 0 < 4.1.3
phpMyFAQ 4.1.3
