Missing Authorization in phpMyFAQ API Leads to Security Risk
CVE-2026-49205
What is CVE-2026-49205?
The phpMyFAQ application, an open-source FAQ management tool, is exposed to a security vulnerability due to missing authorization checks in its API endpoints. Specifically, versions prior to 4.1.4 fail to enforce proper user role permissions in the CategoryController, FaqController, and QuestionController APIs. While previous updates had addressed authorization issues in the BackupController, four other critical endpoints remain unprotected. These APIs, which include methods for creating and updating categories and FAQs, rely solely on a shared API key rather than validating individual user permissions. This oversight presents a significant risk, allowing unauthorized access and manipulation of data via the affected API endpoints. Users are advised to upgrade to version 4.1.4 to mitigate this vulnerability.
Affected Version(s)
phpMyFAQ < 4.1.4
