PT-2026-85491 · Phpmyfaq · Phpmyfaq

·

CVE-2026-85591

·

Published

2026-08-20

·

Updated

2026-09-04

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.8
Description An authentication bypass exists in the user control panel API endpoint. Authenticated attackers with session access can change any user's password, including administrators, without verifying the current password. This is achieved by submitting a PUT request to the user data update endpoint using only a CSRF token, leading to irreversible account takeover and victim lockout.
Recommendations Update to version 4.1.8 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14240
CVE-2026-85591
GHSA-6R2C-694W-24QV

Affected Products

Phpmyfaq