


Perceptive Security
SOC/SIEM Consultancy

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrator…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 17:06:19
Source:
nvd.nist.gov
Web Technologies, Identity & Access
phpMyFAQ versions before 4.1.3 contain an insecure direct object reference vulnerability in the admin API user password endpoint. The vulnerability allows authenticated administrators to change any user's password without proper authorization verification. Attackers with low-privilege admin credentials can exploit this by modifying the userId parameter in the overwrite-password API request to escalate privileges to SuperAdmin level. This represents a significant privilege escalation vulnerability that compromises the application's access control mechanisms.
Technical details
Mitigation steps:
Affected products:
phpMyFAQ
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35671
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xvp4-phqj-cjr3
https://www.vulncheck.com/advisories/phpmyfaq-insecure-direct-object-reference-in-user-password-api
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
