A vulnerability, which was classified as critical, was found in phpMyFAQ up to 4.1.4. This impacts the function
GroupController::updatePermissions. The manipulation results in improper privilege management.
This vulnerability is cataloged as CVE-2026-57995. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.