Description


phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies user or group permission checks. Attackers connected to the phpmyfaq:mcp:server can issue search queries to retrieve the full question and answer text of active FAQs restricted to specific users or groups.

Related CPE's


Could not find any relations

Weaknesses



CWE-862

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

3.3 · Low

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-11T14:17:04.667Z

2 hours ago

Last modified

2026-10-11T14:17:04.777Z

2 hours ago