Authentication Bypass in phpMyFAQ Affects Database Operations
CVE-2026-75919
6.9MEDIUM
What is CVE-2026-75919?
An authentication bypass vulnerability exists in phpMyFAQ versions prior to 4.1.7, specifically within the SetupController. This flaw allows unauthenticated attackers to execute database migrations and create configuration backups by sending requests to the /api/setup/update-database and /api/setup/backup endpoints. When maintenance mode is enabled, attackers can leverage this vulnerability to disable the maintenance mode, thereby gaining unauthorized access to vital database functions and extracting sensitive database credentials from the ZIP archive generated during the backup process.
Affected Version(s)
phpMyFAQ 0 < 4.1.7
phpMyFAQ 4.1.7
