Back exploit-intel.com CVE-2026-56396: phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights() [HIGH] CVSS 8.8 Exploit Intelligence — Recent CVEs / 4h phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to Super
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
