Authentication Bypass in phpMyFAQ Affects Database Operations
CVE-2026-75919

6.9MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-75919?

An authentication bypass vulnerability exists in phpMyFAQ versions prior to 4.1.7, specifically within the SetupController. This flaw allows unauthenticated attackers to execute database migrations and create configuration backups by sending requests to the /api/setup/update-database and /api/setup/backup endpoints. When maintenance mode is enabled, attackers can leverage this vulnerability to disable the maintenance mode, thereby gaining unauthorized access to vital database functions and extracting sensitive database credentials from the ZIP archive generated during the backup process.

Affected Version(s)

phpMyFAQ 0 < 4.1.7

phpMyFAQ 4.1.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kevinnivekkevin
.