PT-2026-97855 · Phpmyfaq · Phpmyfaq
CVE-2026-56737
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions 3.2.0 through 4.1.5
Description
An authentication bypass exists in the public two-factor authentication (2FA) verification flow. An unauthenticated attacker can take over any account that has 2FA enabled, including administrator accounts, by submitting a numeric
user-id and a valid or brute-forced six-digit TOTP (Time-based One-Time Password) code to the POST /check endpoint. The system fails to verify if the user has already successfully authenticated with a password, effectively reducing the security of 2FA-enabled accounts to a single, guessable factor. This is further exacerbated by the lack of a lockout mechanism for failed TOTP attempts on the affected endpoint.Recommendations
Upgrade to version 4.1.6 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq