PatchSiren cyber security CVE debrief
CVE-2026-46362 thorsten CVE debrief
CVE-2026-46362 is a medium-severity authorization bypass affecting phpMyFAQ before 4.1.2. The issue is described as a failure in AbstractAdministrationController::userHasPermission() to stop execution after sending a forbidden response, which can let authenticated users reach permission-protected admin pages. The exposed data can include admin logs, user records, system information, and application configuration. The CVE was published on 2026-05-15 and later modified on 2026-05-18.
- Vendor
- thorsten
- Product
- phpmyfaq
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-28
Who should care
Organizations running phpMyFAQ, especially teams that expose its admin interface to authenticated users, should treat this as a priority patching issue. Security and operations teams responsible for access control, admin portal hardening, and data exposure review should care most.
Technical summary
The supplied record describes an authorization control failure in phpMyFAQ's admin controller logic. AbstractAdministrationController::userHasPermission() is said to send a forbidden response but continue execution instead of terminating, allowing authenticated attackers to request permission-protected admin URLs and bypass intended access checks. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, and the associated weakness is CWE-863.
Defensive priority
High for any phpMyFAQ deployment still below 4.1.2, because the flaw can expose sensitive administrative information to authenticated users without requiring user interaction. Patch quickly and review exposed admin data paths.
Recommended defensive actions
- Upgrade phpMyFAQ to version 4.1.2 or later.
- Restrict access to administrative interfaces to the smallest possible set of authenticated users.
- Review admin logs, user data, system information, and configuration exposure for unintended access.
- Check any local patches or customizations to ensure forbidden responses terminate execution immediately.
- Monitor authentication and admin-access logs for unusual requests to permission-protected URLs.
Evidence notes
The supplied source corpus identifies phpMyFAQ before 4.1.2 as affected and describes the flaw as a non-terminating permission check in AbstractAdministrationController::userHasPermission(). The record also cites a GitHub Security Advisory and a VulnCheck advisory as references. NVD metadata in the supplied item marks the record as Deferred and lists CWE-863 with the provided CVSS vector.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46362 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46362
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46362 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46362
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-hpgw-ww76-c68r
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/phpmyfaq-authorization-bypass-in-admin-pages-via-non-terminating-permission-check
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.