CVE-2026-85587
Dashboard / Vulnerabilities / CVE-2026-85587
Summary: phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages
Details: phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85587.json, https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6w97-49h8-58wh, https://nvd.nist.gov/vuln/detail/CVE-2026-85587, https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-incorrect-authorization-via-admin-pages
Affected packages
Package
Name:
Purl:
