CVE-2026-56396Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-21: 3Patch / Workaround · 2026-06-21: 2Technical Details · 2026-06-21: 306-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-56396 (CVSS 8.8): phpMyFAQ before 4.1.4 has missing authorization flaws allowing admin privilege escalation. Review and patch if in use: https://nvd.nist.gov/vuln/detail/CVE-2026-56396 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/dqzHnIafvz

    Post summary

    The tweet details a high‑severity privilege‑escalation flaw in phpMyFAQ and urges users to review and apply the available patch, with no evidence of exploitation or PoC.

    0000046
    93 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - phpMyFAQ Privilege Escalation via Missing Authorization (CVE-2026-56396) phpMyFAQ's editUser() and updateUserRights() endpoints fail to verify SuperAdmin status before applying changes. As a result, an authenticated non-SuperAdmin user who holds the edit_user permission can set the is_superadmin flag or grant arbitrary rights to an account. This lets a lower-privileged admin-tier user escalate to full SuperAdmin access over the knowledge base, gaining complete control with high confidentiality, integrity, and availability impact. Exploitation requires only an existing account with edit_user and no user interaction. 👉Upgrade to phpMyFAQ 4.1.4.

    Post summary

    CVE‑2026‑56396 enables privilege escalation in phpMyFAQ due to missing authorization checks, allowing authenticated users with edit_user permission to grant themselves full SuperAdmin rights; upgrading to version 4.1.4 mitigates the issue.

    0000065
    223 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56396 Privilege Escalation in phpMyFAQ Before 4.1.4 via Missing Authorization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56396

    Post summary

    This brief entry announces a new privilege‑escalation vulnerability (CVE‑2026‑56396) affecting phpMyFAQ before version 4.1.4, while providing only the basic classification and linking to a vulnerability database page.

    0000054
    4.1K followersView on X

Explore more