Unauthenticated Two-Factor Authentication Flaw in phpMyFAQ by phpMyFAQ Team
CVE-2026-45010
9.1CRITICAL
What is CVE-2026-45010?
The phpMyFAQ software before version 4.1.2 is vulnerable to a serious flaw that allows unauthenticated attackers to exploit the /admin/check endpoint. This vulnerability permits the submission of arbitrary user-id parameters, which, combined with the absence of session binding and rate limiting, enables attackers to initiate brute-force attacks against any user's six-digit TOTP code. Successfully bypassing two-factor authentication can grant the attacker full administrative access to the phpMyFAQ system.
Affected Version(s)
phpmyfaq 0 < 4.1.2
phpmyfaq 4.1.2
