Missing Authorization in phpMyFAQ - #VU137462
Published: July 14, 2026
phpMyFAQ
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to missing authorization in the admin API user/add endpoint when handling crafted user-creation requests with the isSuperAdmin flag. A remote user can create a new account with superadmin privileges and an attacker-chosen password to escalate privileges.
Exploitation requires delegated user-management permissions and no user interaction.