Beveiligingsadvies

CVE-2026-66399

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-27 15:43:48
Laatst bijgewerkt 2026-08-18 11:18:01
Toegewezen door VulnCheck
CVSS-score 8.5
Status PUBLISHED

Beschrijving

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding user-management rights and immediately inherit those permissions to modify or delete user accounts.