CVE-2026-46359: phpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields
phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break out of string literals and execute arbitrary database queries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46359?
CVE-2026-46359 has a high severity rating due to its potential to allow authenticated attackers to execute arbitrary SQL queries.
How do I fix CVE-2026-46359?
To fix CVE-2026-46359, upgrade phpMyFAQ to version 4.1.2 or later.
Who is affected by CVE-2026-46359?
CVE-2026-46359 affects all versions of phpMyFAQ prior to 4.1.2.
What type of vulnerability is CVE-2026-46359?
CVE-2026-46359 is an SQL injection vulnerability.
What is the impact of CVE-2026-46359?
The impact of CVE-2026-46359 includes the potential for attackers to manipulate database queries and access sensitive data.