Remote Code Execution Vulnerability in phpMyFAQ by phpMyFAQ Team
CVE-2026-66398

9.4CRITICAL

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66398?

The phpMyFAQ application versions before 4.1.6 are susceptible to a remote code execution vulnerability via the configuration API. This flaw allows authenticated administrators possessing CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files. By exploiting the upgrade.lastDownloadedPackage setting, attackers can upload a malicious ZIP file as an attachment, redirect the updater configuration to this file's path, and extract it within the application root, enabling code execution as the web server user.

Affected Version(s)

phpMyFAQ 0 < 4.1.6

phpMyFAQ 4.1.6

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ImDuong
.