Unauthenticated Password Reset Vulnerability in phpMyFAQ Software by phpMyFAQ
CVE-2026-35676
8.8HIGH
What is CVE-2026-35676?
An unauthenticated password reset vulnerability exists in the phpMyFAQ application before version 4.1.3. This flaw enables attackers to exploit the user password update API endpoint, allowing them to change user passwords without the need for token validation. By exploiting this vulnerability, attackers can enumerate a list of valid usernames and email addresses, subsequently triggering unauthorized password changes through PUT requests to the /api/index.php/user/password/update endpoint. This can lead to significant account disruptions and the potential invalidation of credentials for legitimate users, thereby compromising the overall security of the application.
Affected Version(s)
phpMyFAQ 0 < 4.1.3
phpMyFAQ 4.1.3
