Authentication Bypass in phpMyFAQ Allows Unauthorized Password Resets
CVE-2026-35675
8.8HIGH
What is CVE-2026-35675?
phpMyFAQ versions before 4.1.3 suffer from an authentication bypass vulnerability in the password reset endpoint. This flaw enables unauthorized attackers to reset passwords of any user account without proper token verification or email confirmation. Such exploitation can lead to username enumeration, allowing attackers to gain access to valid usernames, intercept plaintext passwords via email, and ultimately achieve full control over user accounts, including those with administrative privileges. This vulnerability poses a significant risk to user security and the integrity of affected systems.
Affected Version(s)
phpMyFAQ 0 < 4.1.3
phpMyFAQ 4.1.3
