Description
phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, commenter email addresses, and attachment filenames for FAQ records they cannot directly access by querying the comments and attachments API endpoints.
Published: 2026-08-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

phpMyFAQ before version 4.1.7 does not enforce parent FAQ visibility checks before serving child resources such as comments and attachments. Consequently, unauthenticated users can call the comments and attachments API endpoints and obtain restricted comment text, commenter e‑mail addresses, and attachment filenames for FAQ records that they should not be able to view. This flaw represents a missing authorization mechanism (CWE‑862) and results in a confidentiality compromise of user data and potentially sensitive file names.

Affected Systems

All installations of phpMyFAQ prior to version 4.1.7 are affected. The vulnerability is present in the thorsten's phpMyFAQ package, so any deployment that uses an older release will be susceptible unless the application is upgraded.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity issue. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is sending unauthenticated HTTP requests to the publicly exposed comments and attachments API endpoints. No authentication is required to trigger the flaw, and there are no known active exploits or zero‑day reports as of this analysis, but the ease of manipulation and the lack of access controls make the risk moderate and warranting timely remediation.

Generated by OpenCVE AI on August 20, 2026 at 16:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade phpMyFAQ to version 4.1.7 or newer.
  • Configure the web server or application firewall to restrict unauthenticated access to the comments and attachments API endpoints.
  • Monitor system logs for attempts to access comment or attachment resources without proper authorization.

Generated by OpenCVE AI on August 20, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Thorsten
Thorsten phpmyfaq
Vendors & Products Thorsten
Thorsten phpmyfaq

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, commenter email addresses, and attachment filenames for FAQ records they cannot directly access by querying the comments and attachments API endpoints.
Title phpMyFAQ before 4.1.7 Missing Authorization via child resources
First Time appeared Phpmyfaq
Phpmyfaq phpmyfaq
Weaknesses CWE-862
CPEs cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
Vendors & Products Phpmyfaq
Phpmyfaq phpmyfaq
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Phpmyfaq Phpmyfaq
Thorsten Phpmyfaq
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-21T19:26:45.651Z

Reserved: 2026-08-19T11:35:13.689Z

Link: CVE-2026-76215

cve-icon Vulnrichment

Updated: 2026-08-21T19:26:41.678Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:47.607

Modified: 2026-09-01T15:20:04.380

Link: CVE-2026-76215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:45:16Z

Weaknesses