Missing Authorization in phpMyFAQ API Leads to Security Risk
CVE-2026-49205

6.5MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
18 June 2026

What is CVE-2026-49205?

The phpMyFAQ application, an open-source FAQ management tool, is exposed to a security vulnerability due to missing authorization checks in its API endpoints. Specifically, versions prior to 4.1.4 fail to enforce proper user role permissions in the CategoryController, FaqController, and QuestionController APIs. While previous updates had addressed authorization issues in the BackupController, four other critical endpoints remain unprotected. These APIs, which include methods for creating and updating categories and FAQs, rely solely on a shared API key rather than validating individual user permissions. This oversight presents a significant risk, allowing unauthorized access and manipulation of data via the affected API endpoints. Users are advised to upgrade to version 4.1.4 to mitigate this vulnerability.

Affected Version(s)

phpMyFAQ < 4.1.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.