CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-57996

highCVSS 8.8covered by 1 sourcefirst seen 2026-07-15
phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with isSuperAdmin: true and attacker-chosen credentials to create a SuperAdmin account, then authenticate as that account to achieve full instance takeover.

⚡ Watch CVE-2026-57996

Get an email if CVE-2026-57996 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-57996

CVE.org record

Embed the live status

CVE-2026-57996 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-57996 status](https://www.csirts.com/badge/CVE-2026-57996)](https://www.csirts.com/cve/CVE-2026-57996)