Authentication Bypass Vulnerability in phpMyFAQ by phpMyFAQ Team
CVE-2026-76208
8.8HIGH
What is CVE-2026-76208?
The phpMyFAQ application versions 3.1.0 through 4.1.6 are susceptible to an authentication bypass flaw due to improper handling of LDAP authentication. When LDAP authentication is active and a user successfully binds, the system incorrectly changes the status of a locally blocked account to 'active' without appropriate logging. This allows previously blocked users to regain access unnoticed, posing significant security risks to administrators. This vulnerability was addressed in version 4.1.7.
Affected Version(s)
phpMyFAQ 0
