github.com
https://github.com/thorsten/phpMyFAQ CVE-2026-45007
MEDIUM
phpMyFAQ - Missing Permission Check on 12 Configuration API Endpoints Allows Information Disclosure
Record summary
CVE-2026-45007 has a selected CVSS score of 5.3 (medium).
Description
phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authenticated user can enumerate system configuration metadata including permission model, cache backend, mail provider, and translation provider by querying /admin/api/configuration endpoints, violating least privilege access control.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
phpmyfaqBrowse thorsten / phpmyfaqDefault status: unaffected | CVE List | Before 4.1.2 | affected |
| 4.1.2 | unaffected | ||
phpmyfaq/phpmyfaqBrowse Packagist / phpmyfaq/phpmyfaq | GitHub Advisory | Before 4.1.2 · Fixed in 4.1.2 | affected |
thorsten/phpmyfaqBrowse Packagist / thorsten/phpmyfaq | GitHub Advisory | Before 4.1.2 · Fixed in 4.1.2 | affected |
References
4GHSA Advisory GHSA-rm98-82fr-mcfxVendor advisory
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-rm98-82fr-mcfx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-45007 VulnCheck Advisory: phpMyFAQ - Missing Permission Check on 12 Configuration API Endpoints Allows Information DisclosureThird-party advisory
https://www.vulncheck.com/advisories/phpmyfaq-missing-permission-check-on-12-configuration-api-endpoints-allows-information-disclosure