Two-Factor Authentication Bypass in phpMyFAQ by phpMyFAQ GmbH
CVE-2026-76207

8.6HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76207?

Prior to version 4.1.7, phpMyFAQ has a vulnerability allowing attackers to bypass two-factor authentication (2FA) by exploiting the remember-me token mechanism. Attackers with valid credentials can acquire a remember-me cookie before completing the 2FA challenge, enabling unauthorized access to the application. By replaying the obtained cookie, users can authenticate without the requirement of the second factor, thereby compromising the integrity of the authentication process.

Affected Version(s)

phpMyFAQ 0 < 4.1.7

phpMyFAQ 4.1.7

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pavelkohout396
.