CVE-2026-24420

phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attachments due to a incomprehensive permissions check. The presence of a right key is improperly validated as proof of authorization in attachment.php. Additionally, the group and user permission logic contains a flawed conditional expression that may allow unauthorized access. This issue has been fixed in version


We have discovered 213 live websites that are affected by CVE-2026-24420.

Run a Free Instant Scan




Affected Software

Product  phpMyFAQ
Category Miscellaneous
Vulnerable Domains213 live websites (100% of phpMyFAQ install base)
Vulnerable Versions
  • from 0 through 4.0.17
Vulnerable Versions Count43 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Jan 24, 2026
  • Updated - Jan 26, 2026

Website Distribution by Country

Number of websites using CVE-2026-24420
United States41 websites



Germany91 websites
France11 websites
Japan10 websites
Netherlands6 websites
Switzerland6 websites
Brazil5 websites
Australia3 websites
GB3 websites
Singapore3 websites

Website Distribution by TLD

Number of websites using CVE-2026-24420
.com59 websites
.de58 websites
.net14 websites
.org9 websites
.nl6 websites
.fr5 websites
.info5 websites
.com.br4 websites
.ch3 websites
.jp3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-24420

Top websites that are affected by CVE-2026-24420. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*************.de Germany**,***
***.********.de Germany***,***
*************.org United States***,***
****.**********.com United States***,***
***.*******.**.th Thailand***,***
***.*******.com United States***,***
***.****.de Germany***,***
***.***************.de Germany***,***
*********.com Austria*,***,***
***.******.com United States*,***,***
See full domain list

FAQ

CVE-2026-24420 is Improper Access Control in phpMyFAQ
A total of 213 websites have been identified as vulnerable to CVE-2026-24420, based on global website indexing conducted by WebTechSurvey.
The phpMyFAQ is affected by the CVE-2026-24420 vulnerability.
phpMyFAQ versions up to 4.0.17 are vulnerable to CVE-2026-24420.
CVE-2026-24420 is resolved in version 4.0.17 of phpMyFAQ.