HIGHCVE-2026-46362Published Modified CNA VulnCheck
CVE-2026-46362: phpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission Check
phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs as authenticated users, exposing admin logs, user data, system information, and application configuration.
Metrics
- CVSS v4.0
- 7.1
- Severity
- HIGH
- Fixed in
- 4.1.2
- Affected Products
- 1
Fix available
4.1.2
Affected packages
- thorsten / phpmyfaq< 4.1.2 (from 0)Fixed in 4.1.2
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N