Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85587— phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages

Quick assessment

Affected
thorsten phpMyFAQ
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

phpMyFAQ 4.1.8 之前的版本对管理内容页面实施不正确的权限检查,使得权限较低的编辑人员能够读取草稿和未发布的内容。攻击者若仅拥有“添加”权限,也可以通过访问新闻编辑和 FAQ 翻译端点来查看公众不可见的未发布内容。

CVSS 5.3 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
thorsten phpMyFAQ < 4.1.8 affected
4.1.8 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85587

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages
Source: CVE Program / CVE List V5
Vulnerability Description
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
thorsten phpMyFAQ 0 ~ 4.1.8 -

II. Public POCs for CVE-2026-85587

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85587

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85587 (2)

Same Patch Batch · thorsten · 2026-09-04 · 8 CVEs total

CVE-2026-85591 7.1 HIGH phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
CVE-2026-85590 7.1 HIGH phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
CVE-2026-85586 6.9 MEDIUM phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
CVE-2026-85593 5.4 MEDIUM phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode
CVE-2026-85588 5.3 MEDIUM phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export
CVE-2026-85589 5.3 MEDIUM phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API
CVE-2026-85592 3.7 LOW phpMyFAQ before 4.1.8 Authorization Bypass via question/create

IV. Related Vulnerabilities

V. Comments for CVE-2026-85587

No comments yet


Leave a comment