CVE-2026-85587 Details
Description
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
A vulnerability exists in phpMyFAQ versions prior to 4.1.8, where incorrect permission checks on admin content pages allow lesser-privileged editors to access draft and inactive content. Specifically, users with only add permissions can exploit this issue by accessing news edit and FAQ translate endpoints, thereby viewing unpublished content that is not visible to the public.
Users are advised to update to phpMyFAQ version 4.1.8 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6w97-49h8-58wh | CISA-ADP | AdvisoryExploitRemedyTechnical DescriptionVendor |
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6w97-49h8-58wh | [email protected] | AdvisoryExploitRemedyTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-incorrect-authorization-via-admin-pages | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| phpMyFAQ | <= 4.1.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion