๐Ÿ” CVE Alert

CVE-2026-85589

UNKNOWN 0.0

phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search statistics and content-health counters regardless of their privilege level.

CWE CWE-862
Vendor thorsten
Product phpmyfaq
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for thorsten phpmyfaq

Be the first to know when new unknown vulnerabilities affecting thorsten phpmyfaq are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

thorsten / phpMyFAQ
0 < 4.2.0-alpha.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-gpwm-82cg-4wfw vulncheck.com: https://www.vulncheck.com/advisories/phpmyfaq-before-4.2.0-alpha.2-missing-authorization-via-dashboard-api

Credits

๐Ÿ” skeletonsec