CVE Feed

    Dashboard / CVE / CVE-2026-66398

    CVE-2026-66398

    phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a malicious ZIP file as an attachment, point the updater configuration to its stored path, and extract it into the application root to achieve code execution as the web server user.

    Published:Jul 27, 2026
    Last Modified:Jul 28, 2026
    EPS:Jul 27, 2026
    EPSS Score:
    CVSS Score:9.4

    Affected Products

    Vendor
    Phpmyfaq
    Product
    Phpmyfaq
    Vendor
    Thorsten
    Product
    Phpmyfaq

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High