Unauthenticated Password Reset Vulnerability in phpMyFAQ Software by phpMyFAQ
CVE-2026-35676

8.8HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-35676?

An unauthenticated password reset vulnerability exists in the phpMyFAQ application before version 4.1.3. This flaw enables attackers to exploit the user password update API endpoint, allowing them to change user passwords without the need for token validation. By exploiting this vulnerability, attackers can enumerate a list of valid usernames and email addresses, subsequently triggering unauthorized password changes through PUT requests to the /api/index.php/user/password/update endpoint. This can lead to significant account disruptions and the potential invalidation of credentials for legitimate users, thereby compromising the overall security of the application.

Affected Version(s)

phpMyFAQ 0 < 4.1.3

phpMyFAQ 4.1.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kitu232
.