What is CVE-2026-66399?
CVE-2026-66399 is a privilege escalation vulnerability in phpMyFAQ versions before 4.1.6 within GroupController::updateMembers(). It allows administrators with limited group-management permissions to join privileged groups without proper rights verification. Upgrading to phpMyFAQ 4.1.6 or later is recommended.
Azərbaycanca: CVE-2026-66399 phpMyFAQ 4.1.6 öncəsi versiyalarda GroupController::updateMembers() funksiyasında imtiyaz artırma zəifliyidir. Yalnız qrup idarəetmə icazəsinə malik adminlərə əlavə yoxlama olmadan imtiyazlı qruplara qoşulmağa imkan verir. phpMyFAQ-ni 4.1.6 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
In which function is the CVE-2026-66399 vulnerability located in phpMyFAQ?
The vulnerability is located in the GroupController::updateMembers() function.
To which version is it recommended to upgrade in order to fix CVE-2026-66399?
It is recommended to upgrade to phpMyFAQ version 4.1.6 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.