Incorrect authorization in phpMyFAQ - #VU140886
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass an administrative account block and regain access to the application.
The vulnerability exists due to improper access control in the LDAP authentication flow when processing a successful LDAP login for a pre-existing blocked local account. A remote attacker can authenticate with valid LDAP credentials matching a blocked local account to bypass an administrative account block and regain access to the application.
The blocked-to-active state change is not logged as a security event.