Missing Authorization Vulnerability in phpMyFAQ Admin Dashboard by phpMyFAQ
CVE-2026-85589
5.3MEDIUM
What is CVE-2026-85589?
phpMyFAQ versions prior to 4.2.0-alpha.2 are susceptible to a missing authorization vulnerability found within the admin dashboard API endpoints, specifically the searches and content-health features. This flaw allows any authenticated user to access these endpoints without appropriate permission checks, granting them the ability to view sensitive site-wide search statistics and content-health counters, irrespective of their user privilege level.
Affected Version(s)
phpMyFAQ 0 < 4.2.0-alpha.2
phpMyFAQ 4.2.0-alpha.2
