phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints. Non-SuperAdmin users with edit_user permission can set the is_superadmin flag or grant arbitrary rights to escalate their privileges to SuperAdmin access.
An authenticated non-SuperAdmin user with edit_user permission can escalate their own privileges to SuperAdmin access by modifying the is_superadmin flag or granting themselves arbitrary administrator rights via the editUser() and updateUserRights() endpoints.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patch is available in phpMyFAQ 4.1.4 and later versions.
Upgrade phpMyFAQ to version 4.1.4 or later. Review access controls on the editUser() and updateUserRights() endpoints to ensure proper authorization checks are in place before permitting privilege modifications. Audit user accounts with edit_user permissions to identify any unauthorized privilege escalations. Restrict edit_user permission to trusted administrators only.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-56396 . See article
NVD published the first details for CVE-2026-56396
A CVSS base score of 8.8 has been assigned.
GitHub Advisories released a security advisory .
CVE-2026-56396 - phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights() CVE ID : CVE-2026-56396 Published : June 21, 2026, 1:27 p.m. | 3 hours, 43 minutes ago Description : phpMyFAQ before 4.1.4 contains missing authorization vulne...
CVE-2026-56396: phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights() [HIGH] CVSS 8.8
CVE-2026-56396 | phpMyFAQ up to 4.1.3 editUser/updateUserRights authorization (GHSA-985r-q3qp-299h)
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
