CVE-2026-66399 | thorsten phpMyFAQ up to 4.1.5 Group Controller updateMembers privileges management
A vulnerability marked as problematic has been reported in thorsten phpMyFAQ up to 4.1.5. This vulnerability affects the function GroupController::updateMembers of the component Group Controller. This manipulation causes improper privilege management.
This vulnerability is registered as CVE-2026-66399. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.