Authentication Bypass Vulnerability in phpMyFAQ Affects Multiple Versions
CVE-2026-56737
What is CVE-2026-56737?
phpMyFAQ is a widely-used open-source FAQ web application that has a security flaw in its two-factor authentication verification process. This issue allows unauthorized attackers to bypass the authentication process by submitting a valid six-digit TOTP code linked to any user's numeric ID without needing the account password. As a result, an attacker could potentially take control over any account protected by two-factor authentication, including those of administrators. The vulnerability has been addressed in version 4.1.6, which requires successful password authentication before verifying TOTP codes and limits the number of failed attempts. Users of affected versions are strongly advised to upgrade to version 4.1.6 or later to ensure their accounts remain secure.
Affected Version(s)
phpMyFAQ >= 3.2.0, < 4.1.6
