CVE-2026-85587

NONE
CVSS v3
CVSS v2
0.34% EPSS (exploit probability)
CWE-863CWE

Description

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references