CVE-2026-108851 PUBLISHED

phpMyFAQ through 4.1.10 Missing Authorization via MCP Server faq_search Tool

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies user or group permission checks. Attackers connected to the phpmyfaq:mcp:server can issue search queries to retrieve the full question and answer text of active FAQs restricted to specific users or groups.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor thorsten
Product phpMyFAQ
Versions Default: unaffected
  • affected from 4.1.0 to 4.1.10 (incl.)

Credits

  • hieuPenguinnn finder

References

Problem Types

  • Missing Authorization CWE