CVE-2026-57995

HIGH

phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions

Title source: cna
STIX 2.1

Description

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A delegated administrator can exploit this by assigning high-value permissions to a group they belong to, inheriting those rights and escalating privileges up to full administrative control.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-pg62-f8g4-4wqh)
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-pg62-f8g4-4wqh
Third Party Advisory third-party-advisory
VulnCheck Advisory: phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions
https://www.vulncheck.com/advisories/phpmyfaq-privilege-escalation-via-missing-self-rights-constraint-in-groupcontroller-updatepermissions

Scores

CVSS v3 8.8
EPSS 0.0032
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
phpMyFAQ/phpMyFAQ < 4.1.5
phpMyFAQ/phpMyFAQ 4.1.5
Published Jun 30, 2026
Tracked Since Jul 01, 2026