<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 09:49:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322430</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322430</link>
      <description>EUVD-2026-322430</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322430</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45009</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45009</link>
      <description>&lt;p&gt;phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user accounts can access sensitive backend operational information including dashboard versions, LDAP configuration, Elasticsearch statistics, and health-check data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user accounts can access sensitive backend operational information including dashboard versions, LDAP configuration, Elasticsearch statistics, and health-check data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45009</guid>
    </item>
    <item>
      <title>GHSA-jrc5-w569-h7h5 — phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in ph…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jrc5-w569-h7h5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A review of `phpMyFAQ-main` uncovered an authorization issue in the `admin-api` routes.&lt;/p&gt;
&lt;p&gt;Several backend endpoints only check whether the caller is logged in. They do not verify that the caller actually has backend or administrative privileges. As a result, a normal frontend user can access API endpoints that are clearly intended for administrative use.&lt;/p&gt;
&lt;p&gt;During local reproduction, a regular user account was able to request `/admin/api/index.php/dashboard/versions` and receive a successful response from the backend management API.&lt;/p&gt;
&lt;p&gt;This issue does not appear to give direct write access in the affected paths that were confirmed, so it should be treated as a backend information disclosure and privilege boundary failure rather than full admin compromise.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The access control split is visible in the controller base class:&lt;/p&gt;
&lt;p&gt;```php
public function userIsAuthenticated(): void
{
    if (!$this-&amp;gt;currentUser-&amp;gt;isLoggedIn()) {
        throw new UnauthorizedHttpException(&amp;#39;Unauthorized access.&amp;#39;);
    }
}&lt;/p&gt;
&lt;p&gt;protected function userHasPermission(PermissionType $permissionType): void
{
    // permission-based check
}
```&lt;/p&gt;
&lt;p&gt;The problem is that several `Administration\Api` controllers use the weaker check even though the routes sit under the backend API namespace.&lt;/p&gt;
&lt;p&gt;For example, `phpmyfaq/src/phpMyFAQ/Controller/Administration/Api/DashboardController.php` exposes:&lt;/p&gt;
&lt;p&gt;```php
#[Route(path: &amp;#39;dashboard/versions&amp;#39;, name: &amp;#39;admin.api.dashboard.versions&amp;#39;, methods: [&amp;#39;GET&amp;#39;])]
public fun…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A review of `phpMyFAQ-main` uncovered an authorization issue in the `admin-api` routes.&lt;/p&gt;
&lt;p&gt;Several backend endpoints only check whether the caller is logged in. They do not verify that the caller actually has backend or administrative privileges. As a result, a normal frontend user can access API endpoints that are clearly intended for administrative use.&lt;/p&gt;
&lt;p&gt;During local reproduction, a regular user account was able to request `/admin/api/index.php/dashboard/versions` and receive a successful response from the backend management API.&lt;/p&gt;
&lt;p&gt;This issue does not appear to give direct write access in the affected paths that were confirmed, so it should be treated as a backend information disclosure and privilege boundary failure rather than full admin compromise.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The access control split is visible in the controller base class:&lt;/p&gt;
&lt;p&gt;```php
public function userIsAuthenticated(): void
{
    if (!$this-&amp;gt;currentUser-&amp;gt;isLoggedIn()) {
        throw new UnauthorizedHttpException(&amp;#39;Unauthorized access.&amp;#39;);
    }
}&lt;/p&gt;
&lt;p&gt;protected function userHasPermission(PermissionType $permissionType): void
{
    // permission-based check
}
```&lt;/p&gt;
&lt;p&gt;The problem is that several `Administration\Api` controllers use the weaker check even though the routes sit under the backend API namespace.&lt;/p&gt;
&lt;p&gt;For example, `phpmyfaq/src/phpMyFAQ/Controller/Administration/Api/DashboardController.php` exposes:&lt;/p&gt;
&lt;p&gt;```php
#[Route(path: &amp;#39;dashboard/versions&amp;#39;, name: &amp;#39;admin.api.dashboard.versions&amp;#39;, methods: [&amp;#39;GET&amp;#39;])]
public fun…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jrc5-w569-h7h5</guid>
    </item>
  </channel>
</rss>
