phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user to access sensitive administrative data. Attackers can retrieve LDAP server topology, bind account names, search bases, index statistics, and site analytics by calling these endpoints with a valid session.
References
| Link | Resource |
|---|---|
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-7gh7-qh7c-9r8m | Exploit Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/phpmyfaq-before-information-disclosure-via-admin-api | Third Party Advisory |
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-7gh7-qh7c-9r8m | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-19 14:17
Updated : 2026-09-01 15:21
NVD link : CVE-2026-76211
Mitre link : CVE-2026-76211
CVE.ORG link : CVE-2026-76211
JSON object : View
Products Affected
phpmyfaq
- phpmyfaq
CWE
CWE-862
Missing Authorization
