CVE-2026-66399

Summary

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding user-management rights and immediately inherit those permissions to modify or delete user accounts.

Affected Software

VendorProductVersion RangeStatus
thorstenphpMyFAQ0 < 4.1.6affected
thorstenphpMyFAQ4.1.6unaffected

Weaknesses

  • CWE-269: Improper Privilege Management

References