Missing Authorization Vulnerability in phpMyFAQ Admin Dashboard by phpMyFAQ
CVE-2026-85589

5.3MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85589?

phpMyFAQ versions prior to 4.2.0-alpha.2 are susceptible to a missing authorization vulnerability found within the admin dashboard API endpoints, specifically the searches and content-health features. This flaw allows any authenticated user to access these endpoints without appropriate permission checks, granting them the ability to view sensitive site-wide search statistics and content-health counters, irrespective of their user privilege level.

Affected Version(s)

phpMyFAQ 0 < 4.2.0-alpha.2

phpMyFAQ 4.2.0-alpha.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skeletonsec
.