Remote Code Execution Vulnerability in phpMyFAQ by phpMyFAQ Team
CVE-2026-66398
9.4CRITICAL
What is CVE-2026-66398?
The phpMyFAQ application versions before 4.1.6 are susceptible to a remote code execution vulnerability via the configuration API. This flaw allows authenticated administrators possessing CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files. By exploiting the upgrade.lastDownloadedPackage setting, attackers can upload a malicious ZIP file as an attachment, redirect the updater configuration to this file's path, and extract it within the application root, enabling code execution as the web server user.
Affected Version(s)
phpMyFAQ 0 < 4.1.6
phpMyFAQ 4.1.6
