
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24421 is a missing authorization vulnerability in phpMyFAQ, an open-source FAQ web application, that allows any authenticated user to access the /api/setup/backup endpoint regardless of their privilege level. Affected versions are 4.0.16 and below; the issue is fixed in version 4.0.17. It was published on January 24, 2026, with the security advisory credited to researcher Brahim-Fouad. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is a missing authorization check (CWE-862) in SetupController.php, which guards the /api/setup/backup endpoint using only userIsAuthenticated() — verifying that a session exists — but never validates whether the authenticated user holds configuration or admin-level permissions. An attacker with any valid low-privilege account can send a POST request to the endpoint, triggering a configuration backup and receiving the path to the generated ZIP archive in the response. The precondition is that the phpMyFAQ API is enabled and the attacker possesses valid credentials for any user account. A public proof-of-concept using curl is included in the official advisory (GitHub Advisory).
Successful exploitation allows a low-privileged authenticated user to generate and retrieve a sensitive configuration backup ZIP file that should be restricted to administrators. If the server is misconfigured such that the backup directory is web-accessible, this can lead to direct exposure of secrets, database credentials, API keys, and other sensitive configuration data stored within phpMyFAQ. The impact is limited to confidentiality (rated High), with no integrity or availability impact; however, exposed credentials could enable further lateral movement or privilege escalation within the environment (GitHub Advisory, Feedly).
A public proof-of-concept exploit is available in the official GitHub security advisory and has been indexed by Sploitus (EDB-ID:52523) and referenced on Exploit-DB. The EPSS score is approximately 0.014% (0.000140), indicating low predicted exploitation probability at this time. There is no evidence of active in-the-wild exploitation as of the latest available data, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory, Feedly).
/api/ endpoints.curl -c /tmp/pmf_api_cookies.txt \
-H 'Content-Type: application/json' \
-d '{"username":"tester","password":"Test1234!"}' \
http://<target>/phpmyfaq/api/v3.0/logincurl -i -b /tmp/pmf_api_cookies.txt \
-X POST --data '4.0.16' \
http://<target>/phpmyfaq/api/setup/backup/api/setup/backup originating from non-admin user sessions; repeated API login requests followed immediately by backup endpoint calls from the same source IP.POST /phpmyfaq/api/setup/backup from authenticated sessions belonging to non-administrative accounts; HTTP 200 responses to this endpoint for low-privilege users.The vendor has released phpMyFAQ version 4.0.17, which fixes the missing authorization check in SetupController.php by adding proper permission verification for the /api/setup/backup endpoint. All installations running version 4.0.16 or below should upgrade to 4.0.17 immediately. As a temporary workaround for environments unable to patch immediately, implement network-level access controls (e.g., WAF rules or reverse proxy restrictions) to block access to the /api/setup/backup endpoint for non-administrative users, and monitor access logs for suspicious activity on this endpoint (GitHub Advisory).
The vulnerability was reported by researcher Brahim-Fouad and disclosed via the phpMyFAQ GitHub security advisory program. The issue was noted on Bluesky by automated CVE tracking accounts and indexed by multiple vulnerability aggregators including Vulners, VulDB, and Sploitus shortly after disclosure. No major vendor statements beyond the official advisory or significant media coverage have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."