CVE-2026-56396 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
June 21, 2026
Last Seen
June 21, 2026

CVE-2026-56396 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

CVE-2026-56396 is a vulnerability tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed June 21, 2026; most recent activity June 21, 2026.

Related Threat Clusters

  • Critical Vulnerability in phpMyFAQ Allows Privilege Escalation

    A critical vulnerability, CVE-2026-56396, has been identified in phpMyFAQ versions prior to 4.1.4. This vulnerability allows authenticated non-SuperAdmin users with edit_user permissions to escalate their privileges to…

    3 articles · Updated June 21, 2026

Recent Intelligence Reports

  • CVE-2026-56396 AKAOMA CVE VULNERABILITIES / 7h phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access. — cve.akaoma.com · June 21, 2026
  • CVE-2026-56396: phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights() [HIGH] CVSS 8.8 Exploit Intelligence — Recent CVEs / 4h phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to Super — exploit-intel.com · June 21, 2026
  • CVE-2026-56396 - Exploits & Severity — Feedly · June 21, 2026

Frequently asked questions

What is CVE-2026-56396?

CVE-2026-56396 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Is CVE-2026-56396 still active?

The most recent intelligence report mentioning CVE-2026-56396 on ThreatCluster is dated June 21, 2026.

What is CVE-2026-56396 associated with?

Across ThreatCluster reporting, CVE-2026-56396 most frequently co-occurs with Privilege Escalation, CWE-269 - Improper Privilege Management, CWE-862 - Missing Authorization, T1068 - Exploitation for Privilege Escalation, PhpMyFAQ.

What are the latest developments involving CVE-2026-56396?

The most significant recent cluster is “Critical Vulnerability in phpMyFAQ Allows Privilege Escalation” (3 articles · Updated June 21, 2026). CVE-2026-56396 appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2026-56396?

CVE-2026-56396 appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown