Authentication Bypass Vulnerability in phpMyFAQ Affects Multiple Versions
CVE-2026-56737

8.1HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-56737?

phpMyFAQ is a widely-used open-source FAQ web application that has a security flaw in its two-factor authentication verification process. This issue allows unauthorized attackers to bypass the authentication process by submitting a valid six-digit TOTP code linked to any user's numeric ID without needing the account password. As a result, an attacker could potentially take control over any account protected by two-factor authentication, including those of administrators. The vulnerability has been addressed in version 4.1.6, which requires successful password authentication before verifying TOTP codes and limits the number of failed attempts. Users of affected versions are strongly advised to upgrade to version 4.1.6 or later to ensure their accounts remain secure.

Affected Version(s)

phpMyFAQ >= 3.2.0, < 4.1.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.