CVE-2026-49205 | thorsten phpMyFAQ up to 4.1.3 Public API /api/v4 hasValidToken userHasPermission authorization (GHSA-8c6h-7g6x-m5x4 / EUVD-2026-37954)
A vulnerability labeled as problematic has been found in thorsten phpMyFAQ up to 4.1.3. Affected by this vulnerability is the function hasValidToken of the file /api/v4 of the component Public API. Such manipulation of the argument userHasPermission leads to missing authorization.
This vulnerability is traded as CVE-2026-49205. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.