CVE-2026-85592

    Dashboard / Vulnerabilities / CVE-2026-85592

    CVE-2026-85592

    Published: 4 Sept 2026Last Modified: 10 Sept 2026

    Summary: phpMyFAQ before 4.1.8 Authorization Bypass via question/create

    Details: phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is enabled, ignoring the records.allowQuestionsForGuests setting. Unauthenticated attackers can submit questions via the question/create API endpoint to bypass guest submission restrictions and inject spam into the admin moderation queue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    4.1.7
    4.1.6
    4.1.4
    4.1.3
    4.1.2
    4.1.1
    4.1.0
    4.1.0-RC.7
    4.1.0-RC.6
    4.1.0-RC.5
    4.1.0-RC.4
    4.1.0-RC.2
    4.1.0-RC
    4.1.0-beta.2
    4.1.0-beta
    4.1.0-alpha.3
    4.1.0-alpha.2
    4.1.0-alpha

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-85592 | CVE-DB