---
id: CVE-2026-49205
title: >-
  phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421
  Incomplete Fix)
summary: >-
  phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421
  Incomplete Fix)
severity: medium
cvss: 6.5
cwe:
  - CWE-862
vendor: thorsten
product: thorsten/phpmyfaq
ecosystem: composer
affected:
  - thorsten/phpmyfaq < 4.1.4
  - phpmyfaq/phpmyfaq < 4.1.4
patched:
  - thorsten/phpmyfaq 4.1.4
  - phpmyfaq/phpmyfaq 4.1.4
published: '2026-06-23'
updated: '2026-06-23'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-8c6h-7g6x-m5x4'
references:
  - url: >-
      https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-8c6h-7g6x-m5x4
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49205'
  - url: >-
      https://github.com/thorsten/phpMyFAQ/commit/d5c195b1ecf5dc30fb825d7eb50d22481c24cb07
  - url: 'https://github.com/advisories/GHSA-8c6h-7g6x-m5x4'
tags:
  - ghsa
  - composer
epss: 0.00385
epssPercentile: 0.29697
ingestedAt: '2026-06-26T16:43:14.594Z'
---

## Overview

Missing Authorization in API CategoryController —  CVE-2026-24421 fixed BackupController by adding userHasPermission(PermissionType::BACKUP). The same fix was NOT applied to 4 other write endpoints in the public API.  All 4 only call hasValidToken() (shared API key) but never call userHasPermission(), allowing any API token holder to perform admin operations regardless of their user permissions.

## Summary

CVE-2026-24421 fixed BackupController by adding: $this->userHasPermission(PermissionType::BACKUP);

The same fix was NOT applied to 4 other write endpoints in the public API. All 4 only call $this->hasValidToken() — which checks a shared API key header, NOT the individual user's role permissions.

## Affected Endpoints

1. src/phpMyFAQ/Controller/Api/CategoryController.php → create()  POST /api/v4.0/category
Missing: userHasPermission(PermissionType::CATEGORY_ADD)
Any API token holder can create categories regardless of user role.

2. src/phpMyFAQ/Controller/Api/FaqController.php → create()  POST /api/v4.0/faq
   Missing: userHasPermission(PermissionType::FAQ_ADD)
   Any API token holder can create FAQ entries regardless of user role.

3. src/phpMyFAQ/Controller/Api/FaqController.php → update()  PUT /api/v4.0/faq
   Missing: userHasPermission(PermissionType::FAQ_EDIT)
   Any API token holder can update any FAQ entry regardless of user role.

4. src/phpMyFAQ/Controller/Api/QuestionController.php → create() POST /api/v4.0/question
   Missing: permission check
   Any API token holder can create questions regardless of user role.

## Root Cause

All 4 methods only call:
    $this->hasValidToken();   ← shared API key, not per-user

The fixed BackupController correctly calls:
    $this->userHasPermission(PermissionType::BACKUP);  

PermissionType::CATEGORY_ADD, FAQ_ADD, FAQ_EDIT all exist in src/phpMyFAQ/Enums/PermissionType.php — they just are not being used.

## Fix

Add userHasPermission() before the logic in each method:

    // CategoryController.create()
    $this->userHasPermission(PermissionType::CATEGORY_ADD);

    // FaqController.create()
    $this->userHasPermission(PermissionType::FAQ_ADD);

    // FaqController.update()
    $this->userHasPermission(PermissionType::FAQ_EDIT);

## Reporter

CONTACT
Santhoshini Ganta
Github:@santhoshinipayload
Email: santhoshinive75@gmail.com
LinkedIn: http://linkedin.com/in/santhoshini-g-1440621ba

## Affected packages

- `thorsten/phpmyfaq < 4.1.4`
- `phpmyfaq/phpmyfaq < 4.1.4`

## Remediation

Upgrade to a patched release:

- `thorsten/phpmyfaq 4.1.4`
- `phpmyfaq/phpmyfaq 4.1.4`
