HarborGuard / CVE
Back to search
HIGHCVE-2026-46366Published Modified CNA VulnCheck

CVE-2026-46366: phpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially iterate solution IDs to discover all FAQs including those restricted to specific users or groups, leaking sensitive metadata through redirect Location headers and page canonical links.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
4.1.2
Affected Products
1

Fix available

4.1.2
Affected packages
  • thorsten / phpmyfaq
    < 4.1.2 (from 0)
    Fixed in 4.1.2
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-46366: phpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass | HarborGuard CVE