Brute-Force Vulnerability in phpMyFAQ by ServerGrove
CVE-2026-76213
9.1CRITICAL
What is CVE-2026-76213?
phpMyFAQ versions prior to 4.1.7 implement a flawed brute-force protection mechanism in the two-factor authentication process. The vulnerability arises from a session-scoped failure counter that resets with each successful password re-authentication. This allows attackers, who possess valid credentials, to bypass the intended five-attempt limit by obtaining new session cookies and resetting the counter, enabling them to conduct unlimited guessing attempts on the Time-based One-Time Password (TOTP) codes.
Affected Version(s)
phpMyFAQ 0 < 4.1.7
phpMyFAQ 4.1.7
