MEDIUM
phpMyFAQ - Insufficient Authorization Check in Admin API Endpoints
Published May 15, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.28%
Description
phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user accounts can access sensitive backend operational information including dashboard versions, LDAP configuration, Elasticsearch statistics, and health-check data.
Affected products
-
Affected
- ≥ 4.1.1, < 4.1.2
Unaffected
- 4.1.2
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30592 Advisory
- https://github.com/advisories/GHSA-jrc5-w569-h7h5 Advisory
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-jrc5-w569-h7h5 exploitvendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45009
- https://www.vulncheck.com/advisories/phpmyfaq-insufficient-authorization-check-in-admin-api-endpoints third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30592 | Advisory | |
| https://github.com/advisories/GHSA-jrc5-w569-h7h5 | Advisory | |
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-jrc5-w569-h7h5 | exploitvendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45009 | ||
| https://www.vulncheck.com/advisories/phpmyfaq-insufficient-authorization-check-in-admin-api-endpoints | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 15, 2026
Updated May 28, 2026
Reserved May 8, 2026
Link CVE-2026-45009
CISA Vulnrichment
Updated May 15, 2026
Red Hat
No data
GitHub
Link GHSA-JRC5-W569-H7H5