Authentication Bypass in phpMyFAQ Allows Unauthorized Password Resets
CVE-2026-35675

8.8HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-35675?

phpMyFAQ versions before 4.1.3 suffer from an authentication bypass vulnerability in the password reset endpoint. This flaw enables unauthorized attackers to reset passwords of any user account without proper token verification or email confirmation. Such exploitation can lead to username enumeration, allowing attackers to gain access to valid usernames, intercept plaintext passwords via email, and ultimately achieve full control over user accounts, including those with administrative privileges. This vulnerability poses a significant risk to user security and the integrity of affected systems.

Affected Version(s)

phpMyFAQ 0 < 4.1.3

phpMyFAQ 4.1.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cyberHunter127
.