CVE-2026-66397 HIGH

CVE-2026-66397: phpMyFAQ before 4.1.6 Path Traversal via category image deletion

Vendor Thorsten
Product phpMyFAQ
Weakness CWE-22 · Path traversal
Published July 27, 2026
Last update July 28, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

Key dates

02Disclosure timeline

July 27, 2026 CVE published
July 28, 2026 Record updated

Related vulnerabilities

04Related CVE