What is CVE-2026-75919?
CVE-2026-75919 is an authentication bypass vulnerability in phpMyFAQ before 4.1.7 affecting the SetupController. It allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Immediate update to version 4.1.7 or later is recommended.
Azərbaycanca: CVE-2026-75919, phpMyFAQ proqramının 4.1.7 öncəsi versiyalarında SetupController-də aşkarlanan autentifikasiya bypass zəifliyidir. Texniki xidmət rejimi aktiv olduqda, autentifikasiya olunmamış hücumçuya database migrasiyalarını icra etməyə və konfiqurasiya ehtiyat nüsxələrini yaratmağa imkan verir. Dərhal 4.1.7 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of phpMyFAQ are affected by CVE-2026-75919?
This vulnerability affects versions of phpMyFAQ before 4.1.7. An immediate update to version 4.1.7 or later is recommended to address the issue.
What can an unauthenticated attacker do via the CVE-2026-75919 authentication bypass vulnerability?
An unauthenticated attacker can exploit the vulnerability in the SetupController to run database migrations and create configuration backups when maintenance mode is enabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.