Skip to content
Critical Vulnerability in phpMyFAQ Allows Privilege Escalation

Critical Vulnerability in phpMyFAQ Allows Privilege Escalation

First seen 22 Jun 2026, 00:03 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 22, 2026 at 23:40 UTC
  • CVE-2026-56396 allows privilege escalation for non-SuperAdmin users in phpMyFAQ.
  • The vulnerability affects all versions of phpMyFAQ prior to 4.1.4, with a CVSS score of 8.8.
  • A patch is available; users are advised to upgrade to version 4.1.4 or later immediately.

A critical vulnerability, CVE-2026-56396, has been identified in phpMyFAQ versions prior to 4.1.4. This vulnerability allows authenticated non-SuperAdmin users with edit_user permissions to escalate their privileges to SuperAdmin by modifying the is_superadmin flag through the editUser() and updateUserRights() endpoints. The CVSS base score assigned to this vulnerability is 8.8, indicating a high severity level. Currently, there is no evidence of public proof-of-concept or active exploitation. A patch has been released in phpMyFAQ version 4.1.4, and users are urged to upgrade immediately. Organizations should review access controls and audit user accounts with edit_user permissions to prevent unauthorized privilege escalations. Security professionals consider this vulnerability an immediate threat requiring urgent mitigation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-21
CVE-2026-56396 published
phpMyFAQ vulnerability disclosed, allowing privilege escalation for non-SuperAdmin users.
Feedly
2026-06-21
Security advisory released
GitHub Advisories published a security advisory regarding CVE-2026-56396, detailing the vulnerabilities.
Feedly
2026-06-21
Patch released
A patch was made available in phpMyFAQ version 4.1.4 to address the vulnerability.
Feedly

More articles in this cluster (5)

Following this threat?

Track CVE-2026-56396 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed