PT-2026-97855 · Phpmyfaq · Phpmyfaq

CVE-2026-56737

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions 3.2.0 through 4.1.5
Description An authentication bypass exists in the public two-factor authentication (2FA) verification flow. An unauthenticated attacker can take over any account that has 2FA enabled, including administrator accounts, by submitting a numeric user-id and a valid or brute-forced six-digit TOTP (Time-based One-Time Password) code to the POST /check endpoint. The system fails to verify if the user has already successfully authenticated with a password, effectively reducing the security of 2FA-enabled accounts to a single, guessable factor. This is further exacerbated by the lack of a lockout mechanism for failed TOTP attempts on the affected endpoint.
Recommendations Upgrade to version 4.1.6 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56737
GHSA-8GPW-XVPF-HVX5

Affected Products

Phpmyfaq