PT-2026-78395 · Phpmyfaq · Phpmyfaq

·

CVE-2026-76213

·

Published

2026-08-04

·

Updated

2026-08-19

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.7
Description A flaw exists in the two-factor authentication process where the failure counter is session-scoped and resets upon every successful password re-authentication. An attacker possessing a valid password can bypass the five-attempt limit by acquiring a new session cookie and re-authenticating to reset the counter, allowing for unbounded guessing of the Time-based One-Time Password (TOTP), which is a temporary code generated by an app to provide an extra layer of security.
Recommendations Update to version 4.1.7 or later.

Exploit

Fix

DoS

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12053
CVE-2026-76213
GHSA-F98M-HCJV-7RP9

Affected Products

Phpmyfaq