exploit-intel.com Critical Vulnerability in phpMyFAQ Allows Privilege Escalation
Article Content
- •CVE-2026-56396 allows privilege escalation for non-SuperAdmin users in phpMyFAQ.
- •The vulnerability affects all versions of phpMyFAQ prior to 4.1.4, with a CVSS score of 8.8.
- •A patch is available; users are advised to upgrade to version 4.1.4 or later immediately.
A critical vulnerability, CVE-2026-56396, has been identified in phpMyFAQ versions prior to 4.1.4. This vulnerability allows authenticated non-SuperAdmin users with edit_user permissions to escalate their privileges to SuperAdmin by modifying the is_superadmin flag through the editUser() and updateUserRights() endpoints. The CVSS base score assigned to this vulnerability is 8.8, indicating a high severity level. Currently, there is no evidence of public proof-of-concept or active exploitation. A patch has been released in phpMyFAQ version 4.1.4, and users are urged to upgrade immediately. Organizations should review access controls and audit user accounts with edit_user permissions to prevent unauthorized privilege escalations. Security professionals consider this vulnerability an immediate threat requiring urgent mitigation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-56396 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…