Incorrect authorization in phpMyFAQ - CVE-2026-85587
Published: August 21, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose unpublished content.
The vulnerability exists due to incorrect authorization in admin news edit and faq translate pages when handling requests for protected content records. A remote user can request the affected admin pages with only add-level permissions to disclose unpublished content.
The issue affects inactive news drafts and inactive FAQs that are not publicly accessible.