What is CVE-2026-66397?
CVE-2026-66397 affects phpMyFAQ versions before 4.1.6, where insufficient sanitization in the `existing_image` field during category updates allows authenticated attackers to delete arbitrary files via path traversal in `Image::delete()`. This can lead to the deletion of critical files like database configuration; update to version 4.1.6 immediately to mitigate the risk.
Azərbaycanca: CVE-2026-66397, phpMyFAQ platformasının 4.1.6 versiyasından əvvəlki versiyalarında, autentifikasiya olunmuş hücumçulara `existing_image` sahəsində path traversal zəifliyi vasitəsilə ixtiyari faylları silməyə imkan verir. Sistem konfiqurasiya faylını silmək kimi ciddi nəticələrə səbəb ola bilər; dərhal 4.1.6 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of phpMyFAQ are affected by CVE-2026-66397, and does the attacker need to be authenticated?
The vulnerability affects all phpMyFAQ versions prior to 4.1.6. Yes, the attacker must be authenticated on the platform to exploit this flaw.
What action is required to mitigate CVE-2026-66397?
You should immediately update phpMyFAQ to version 4.1.6 to mitigate this risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.