What is CVE-2026-66398?
This is a remote code execution vulnerability in phpMyFAQ versions before 4.1.6. Authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges can write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting via the configuration API. Users are strongly advised to upgrade to version 4.1.6 or later immediately.
Azərbaycanca: Bu phpMyFAQ-un 4.1.6 öncəsi versiyalarında aşkarlanmış uzaqdan kod icrası zəifliyidir. Autentifikasiyadan keçmiş inzibatçılar 'CONFIGURATION_EDIT' və 'ATTACHMENT_ADD' səlahiyyətləri ilə konfiqurasiya API-si vasitəsilə ixtiyari PHP faylları yaza bilər. İstifadəçilərə dərhal 4.1.6 versiyasına və ya daha yuxarı versiyaya yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What privileges must an attacker have to successfully exploit CVE-2026-66398?
The attacker must be an authenticated administrator in phpMyFAQ with both 'CONFIGURATION_EDIT' and 'ATTACHMENT_ADD' privileges.
What is the primary recommendation to mitigate CVE-2026-66398?
Users are strongly advised to immediately upgrade phpMyFAQ to version 4.1.6 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.