LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-46359

Published
CVSS7.5
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break out of string literals and execute arbitrary database queries.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-46359

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-46359.