Description
phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user to access sensitive administrative data. Attackers can retrieve LDAP server topology, bind account names, search bases, index statistics, and site analytics by calling these endpoints with a valid session.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

phpMyFAQ versions before 4.1.7 do not enforce the CONFIGURATION_EDIT permission on certain admin API read endpoints. As a result, any authenticated user can query the LDAP, Elasticsearch, OpenSearch, and dashboard configuration APIs and obtain detailed administrative data such as LDAP server topology, bind account names, search bases, index statistics, and site analytics. This flaw permits disclosure of sensitive configuration information, potentially aiding attackers in planning further attacks or profiling the environment.

Affected Systems

Thorsten phpMyFAQ installations running any version earlier than 4.1.7 are vulnerable. The issue affects the admin APIs exposed by the phpMyFAQ application when accessed by authenticated users. Users should verify the version of phpMyFAQ deployed in their environments and confirm that it is at least 4.1.7.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. Exploitation requires an already authenticated session; the attacker needs valid credentials or a session cookie. The EPSS score of 0.00204 (less than 1%) indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, the information disclosed could be valuable to anyone who gains login access, so repairs should be applied promptly to prevent unnecessary exposure.

Generated by OpenCVE AI on August 20, 2026 at 17:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade phpMyFAQ to version 4.1.7 or later.
  • Re‑evaluate and restrict the CONFIGURATION_EDIT permission so that only trusted admin accounts possess it.
  • Restrict access to the admin API endpoints using firewall rules or a reverse proxy to allow only approved IP addresses.
  • Monitor access logs for suspicious activity on the admin API routes.

Generated by OpenCVE AI on August 20, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Thorsten
Thorsten phpmyfaq
Vendors & Products Thorsten
Thorsten phpmyfaq

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user to access sensitive administrative data. Attackers can retrieve LDAP server topology, bind account names, search bases, index statistics, and site analytics by calling these endpoints with a valid session.
Title phpMyFAQ before 4.1.7 Information Disclosure via Admin API
First Time appeared Phpmyfaq
Phpmyfaq phpmyfaq
Weaknesses CWE-862
CPEs cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
Vendors & Products Phpmyfaq
Phpmyfaq phpmyfaq
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Phpmyfaq Phpmyfaq
Thorsten Phpmyfaq
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-20T17:24:43.551Z

Reserved: 2026-08-19T11:34:28.576Z

Link: CVE-2026-76211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:46.653

Modified: 2026-09-01T15:21:40.737

Link: CVE-2026-76211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:15:04Z

Weaknesses