CVE-2026-66399
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Jul 27, 2026
Vendor
unknown
Description
phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding user-management rights and immediately inherit those permissions to modify or delete user accounts.