CVE-2026-66398

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a malicious ZIP file as an attachment, point the updater configuration to its stored path, and extract it into the application root to achieve code execution as the web server user.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-27 16:18

Updated : 2026-07-28 16:07


NVD link : CVE-2026-66398

Mitre link : CVE-2026-66398

CVE.ORG link : CVE-2026-66398


JSON object : View

Products Affected

No product.

CWE
CWE-494

Download of Code Without Integrity Check