CVE-2026-45009

Source
https://cve.org/CVERecord?id=CVE-2026-45009
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-45009.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-45009
Aliases
Published
2026-05-15T18:36:36.621Z
Modified
2026-05-30T03:54:23.284368388Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
phpMyFAQ - Insufficient Authorization Check in Admin API Endpoints
Details

phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user accounts can access sensitive backend operational information including dashboard versions, LDAP configuration, Elasticsearch statistics, and health-check data.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45009.json",
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/thorsten/phpmyfaq

Affected ranges

Type
GIT
Repo
https://github.com/thorsten/phpmyfaq
Events

Affected versions

4.*
4.1.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-45009.json"