exploit-intel.com
Critical Vulnerability in phpMyFAQ Allows Privilege Escalation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability, CVE-2026-56396, has been identified in phpMyFAQ versions prior to 4.1.4. This vulnerability allows authenticated non-SuperAdmin users with edit_user permissions to escalate their privileges to SuperAdmin by modifying the is_superadmin flag through the editUser() and updateUserRights() endpoints. The CVSS base score assigned to this vulnerability is 8.8, indicating a high severity level. Currently, there is no evidence of public proof-of-concept or active exploitation. A patch has been released in phpMyFAQ version 4.1.4, and users are urged to upgrade immediately. Organizations should review access controls and audit user accounts with edit_user permissions to prevent unauthorized privilege escalations. Security professionals consider this vulnerability an immediate threat requiring urgent mitigation.
Key Points: • CVE-2026-56396 allows privilege escalation for non-SuperAdmin users in phpMyFAQ. • The vulnerability affects all versions of phpMyFAQ prior to 4.1.4, with a CVSS score of 8.8. • A patch is available; users are advised to upgrade to version 4.1.4 or later immediately.