PT-2026-78396 · Phpmyfaq · Phpmyfaq

·

CVE-2026-76214

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.7
Description The software fails to persist the WebAuthn login challenge generated by the prepareForLogin() function because the WebAuthn controller does not save the mutated key objects back to the database. During the login process, the anti-replay comparison is bypassed by a null guard. This allows an attacker who captures a successful WebAuthn assertion to replay it indefinitely to authenticate as a user without requiring interaction or a hardware key.
Recommendations Update to version 4.1.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76214
GHSA-F534-WV9G-WX2W

Affected Products

Phpmyfaq