Two-Factor Authentication Bypass in phpMyFAQ by phpMyFAQ GmbH
CVE-2026-76207
8.6HIGH
What is CVE-2026-76207?
Prior to version 4.1.7, phpMyFAQ has a vulnerability allowing attackers to bypass two-factor authentication (2FA) by exploiting the remember-me token mechanism. Attackers with valid credentials can acquire a remember-me cookie before completing the 2FA challenge, enabling unauthorized access to the application. By replaying the obtained cookie, users can authenticate without the requirement of the second factor, thereby compromising the integrity of the authentication process.
Affected Version(s)
phpMyFAQ 0 < 4.1.7
phpMyFAQ 4.1.7
