PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35671 thorsten CVE debrief

phpMyFAQ before 4.1.3 contains an insecure direct object reference (IDOR) vulnerability in the admin API user password endpoint. Authenticated administrators with low privileges can change any user's password—including SuperAdmin accounts—by manipulating the userId parameter in overwrite-password API requests, enabling privilege escalation. The vulnerability was disclosed on 2026-05-28 with a CVSS 4.0 score of 8.7 (HIGH severity).

Vendor
thorsten
Product
phpMyFAQ
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-30
Advisory published
2026-05-28
Advisory updated
2026-05-30

Who should care

Organizations running phpMyFAQ versions prior to 4.1.3 with admin API enabled; security teams monitoring for privilege escalation in web applications; administrators responsible for FAQ/knowledge base systems

Technical summary

The vulnerability exists in the admin API's overwrite-password endpoint where the userId parameter is not properly validated against the requesting administrator's authorization scope. An authenticated administrator can supply arbitrary userId values to change passwords for any account including SuperAdmin without additional authorization verification. This represents CWE-266: Incorrect Privilege Assignment through insecure direct object reference. The attack requires network access to the admin API, valid low-privilege admin credentials, and no user interaction.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to phpMyFAQ 4.1.3 or later to remediate the IDOR vulnerability
  • Review admin API access logs for suspicious overwrite-password requests with modified userId parameters
  • Implement additional authorization checks on sensitive admin API endpoints beyond authentication
  • Audit user accounts for unauthorized password changes, particularly SuperAdmin accounts
  • Restrict admin API access to trusted source IP ranges where feasible

Evidence notes

Official vendor advisory confirms IDOR in admin API password endpoint allowing unauthorized password changes. VulnCheck advisory provides additional technical context. CVSS 4.0 vector indicates network attack vector, low attack complexity, low privileges required, and high impact to confidentiality, integrity, and availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35671 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35671

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35671 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35671

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.