CVE-2026-24421: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-24421 is a missing authorization vulnerability in phpMyFAQ, an open-source FAQ web application, that allows any authenticated user to access the /api/setup/backup endpoint regardless of their privilege level. Affected versions are 4.0.16 and below; the issue is fixed in version 4.0.17. It was published on January 24, 2026, with the security advisory credited to researcher Brahim-Fouad. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) in SetupController.php, which guards the /api/setup/backup endpoint using only userIsAuthenticated() — verifying that a session exists — but never validates whether the authenticated user holds configuration or admin-level permissions. An attacker with any valid low-privilege account can send a POST request to the endpoint, triggering a configuration backup and receiving the path to the generated ZIP archive in the response. The precondition is that the phpMyFAQ API is enabled and the attacker possesses valid credentials for any user account. A public proof-of-concept using curl is included in the official advisory (GitHub Advisory).

Impact

Successful exploitation allows a low-privileged authenticated user to generate and retrieve a sensitive configuration backup ZIP file that should be restricted to administrators. If the server is misconfigured such that the backup directory is web-accessible, this can lead to direct exposure of secrets, database credentials, API keys, and other sensitive configuration data stored within phpMyFAQ. The impact is limited to confidentiality (rated High), with no integrity or availability impact; however, exposed credentials could enable further lateral movement or privilege escalation within the environment (GitHub Advisory, Feedly).

Exploitability

A public proof-of-concept exploit is available in the official GitHub security advisory and has been indexed by Sploitus (EDB-ID:52523) and referenced on Exploit-DB. The EPSS score is approximately 0.014% (0.000140), indicating low predicted exploitation probability at this time. There is no evidence of active in-the-wild exploitation as of the latest available data, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing phpMyFAQ instances running version 4.0.16 or earlier. Confirm the REST API is enabled by checking for accessible /api/ endpoints.
  2. Obtain credentials: Acquire any valid low-privilege user account on the target phpMyFAQ instance (e.g., a self-registered account if open registration is enabled).
  3. Authenticate via API: Send a POST request to the login endpoint to obtain a session cookie:
curl -c /tmp/pmf_api_cookies.txt \
  -H 'Content-Type: application/json' \
  -d '{"username":"tester","password":"Test1234!"}' \
  http://<target>/phpmyfaq/api/v3.0/login
  1. Trigger backup: Use the session cookie to POST to the backup endpoint:
curl -i -b /tmp/pmf_api_cookies.txt \
  -X POST --data '4.0.16' \
  http://<target>/phpmyfaq/api/setup/backup
  1. Retrieve backup path: Parse the response for the path or URL to the generated ZIP archive containing the configuration backup.
  2. Download and extract secrets: If the backup directory is web-accessible, download the ZIP and extract database credentials, API keys, and other sensitive configuration data (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /api/setup/backup originating from non-admin user sessions; repeated API login requests followed immediately by backup endpoint calls from the same source IP.
  • Logs: Web server access logs showing POST /phpmyfaq/api/setup/backup from authenticated sessions belonging to non-administrative accounts; HTTP 200 responses to this endpoint for low-privilege users.
  • File System: Newly created ZIP backup files in the phpMyFAQ backup directory at unexpected times or with unusual frequency; backup files accessed or downloaded shortly after creation.
  • Application Logs: phpMyFAQ application logs recording backup generation events initiated by non-admin user accounts (GitHub Advisory).

Mitigation and workarounds

The vendor has released phpMyFAQ version 4.0.17, which fixes the missing authorization check in SetupController.php by adding proper permission verification for the /api/setup/backup endpoint. All installations running version 4.0.16 or below should upgrade to 4.0.17 immediately. As a temporary workaround for environments unable to patch immediately, implement network-level access controls (e.g., WAF rules or reverse proxy restrictions) to block access to the /api/setup/backup endpoint for non-administrative users, and monitor access logs for suspicious activity on this endpoint (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher Brahim-Fouad and disclosed via the phpMyFAQ GitHub security advisory program. The issue was noted on Bluesky by automated CVE tracking accounts and indexed by multiple vulnerability aggregators including Vulners, VulDB, and Sploitus shortly after disclosure. No major vendor statements beyond the official advisory or significant media coverage have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management