LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-35671

Published
CVSS8.8
Severityhigh
WeaknessCWE-266
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-35671

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-35671.