What is CVE-2026-76206?
The CVE-2026-76206 vulnerability in phpMyFAQ versions prior to 4.1.7 stems from missing active status validation in the PDF export endpoint. This allows unauthenticated attackers to access the public PDF export route with sequential FAQ identifiers and retrieve draft FAQ metadata, including titles, solution IDs, author names, and last-update information. Users should upgrade to phpMyFAQ version 4.1.7 or later immediately.
Azərbaycanca: CVE-2026-76206 zəifliyi phpMyFAQ platformasının 4.1.7 öncəsi versiyalarında PDF ixrac funksiyasında aktiv status yoxlamasının olmaması ilə bağlıdır. Bu, autentifikasiya olunmamış hücumçulara ardıcıl FAQ identifikatorları vasitəsilə qaralama (draft) FAQ metadata məlumatlarını (başlıq, həll ID-ləri, müəllif adları və yeniləmə tarixçəsi) əldə etməyə imkan verir. İstifadəçilərə dərhal phpMyFAQ 4.1.7 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ1
Which versions of phpMyFAQ are affected by CVE-2026-76206?
This vulnerability affects phpMyFAQ versions prior to 4.1.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.