Sceawere

Vulnerability Detail

CVE-2026-108851UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

phpMyFAQ Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
3h ago
Vendor
thorsten
Product
phpMyFAQ
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies user or group permission checks. Attackers connected to the phpmyfaq:mcp:server can issue search queries to retrieve the full question and answer text of active FAQs restricted to specific users or groups.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-11T14:17:04.667Z",
  "pubdate": "2026-10-11T14:17:04.667Z",
  "executiveSummary": "A missing authorization vulnerability exists in the MCP (Multi-Content Protocol) server of phpMyFAQ versions through 4.1.10. The vulnerability resides within the search functionality, specifically failing to enforce access control lists (ACLs) or user/group permission checks during database query execution. This flaw allows unauthorized MCP clients to access restricted or private FAQ content that should be hidden based on the user's privilege level. The impact is significant, as an attacker with access to the MCP server can exfiltrate the full text of sensitive knowledge base entries, including questions and answers marked as restricted. This breach of confidentiality compromises the integrity of organizational knowledge management systems. Exploitation does not require elevated privileges, provided the attacker can connect to the vulnerable MCP server endpoint. The risk is high for environments relying on phpMyFAQ to store proprietary or sensitive internal documentation.",
  "technicalDetails": "The root cause of this vulnerability is an authorization bypass within the 'faq_search' tool implemented in the phpMyFAQ MCP server interface. Specifically, the 'Search::searchDatabase()' function serves as the primary backend mechanism for processing search queries. During the execution of this function, the application fails to validate the current user's session state against the defined permissions associated with the FAQ records in the database. Consequently, the query execution logic proceeds to fetch records from the backend store without applying restrictive filters that should limit results based on authenticated user IDs or group memberships.\nThe exploitation process follows a predictable flow. An attacker establishes a connection to the phpmyfaq:mcp:server protocol. Once the connection is active, the attacker issues a search query payload to the 'faq_search' component. Because 'Search::searchDatabase()' does not perform an intermediary validation check to ensure the requester has the necessary authorization to view the specific record, the database layer retrieves the full content of the requested FAQ entry. The server then transmits the sensitive content back to the client interface. This allows an attacker to perform automated data harvesting by iterating through search queries to scrape the entirety of the protected knowledge base.\nThe affected component is the internal search routine within the MCP server implementation of phpMyFAQ. All versions up to and including 4.1.10 are susceptible. The lack of an integrated permission enforcement layer within the 'Search::searchDatabase()' method means that the application defaults to an 'open' access model when queries are processed through this specific interface. This bypasses the standard authentication and authorization logic that typically restricts access to the web-based administrative dashboard or restricted portal views. The post-exploitation impact includes the full disclosure of confidential internal procedures, sensitive configuration data, or private technical insights that were explicitly intended to be segmented from unauthorized users."
}
CVE-2026-108851: phpMyFAQ Missing Authorization Vulnerability (LOW Severity, CVSS: 3.3) | Sceawere