What is CVE-2026-76211?
CVE-2026-76211: In phpMyFAQ versions before 4.1.7, the admin API read endpoints fail to properly enforce CONFIGURATION_EDIT permission. This allows any authenticated user to access sensitive configuration data such as LDAP server topology and bind account details.
Azərbaycanca: CVE-2026-76211: phpMyFAQ 4.1.7-dən əvvəlki versiyalarda admin API-nin oxuma endpoint-lərində CONFIGURATION_EDIT icazəsi düzgün tətbiq edilmir. Bu, autentifikasiya olunmuş istənilən istifadəçiyə LDAP, Elasticsearch və digər həssas konfiqurasiya məlumatlarını əldə etməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which authenticated users are affected by CVE-2026-76211?
The vulnerability affects any authenticated user because the admin API read endpoints do not properly enforce the CONFIGURATION_EDIT permission.
What sensitive data can be accessed via CVE-2026-76211?
Sensitive configuration data such as LDAP server topology, bind account details, and other configurations like Elasticsearch can be accessed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.