Medium severityNVD Advisory· Published Sep 4, 2026
CVE-2026-85587
CVE-2026-85587
Description
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.1.8
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.