What is CVE-2026-75920?
This vulnerability affects phpMyFAQ versions before 4.1.6, where content backup ZIP archives are written to the web-accessible document root, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before it is deleted. Immediate update to the latest version is recommended.
Azərbaycanca: Bu boşluq phpMyFAQ-ın 4.1.6-dan əvvəlki versiyalarında aşkarlanıb və məzmun ehtiyat ZIP arxivlərini veb-əlçatan qovluğa yazaraq verilənlər bazası məlumatları daxil olmaqla həssas faylları ifşa edir. Təcavüzkarlar, autentifikasiyasız şəkildə yarış sorğuları ilə müvəqqəti ZIP faylını silinmədən əvvəl endirə bilər. Dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which product is affected by CVE-2026-75920, and what can an attacker obtain without authentication?
The vulnerability affects phpMyFAQ versions before 4.1.6. An unauthenticated attacker can race concurrent requests to download the temporary ZIP backup file before it is deleted, exposing sensitive files including database credentials that are written to the web-accessible document root.
What is the primary recommended action for CVE-2026-75920?
Immediate update to the latest version of phpMyFAQ is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.