Security Flaw in phpMyFAQ Data Export Allows TOTP Secret Exposure
CVE-2026-85588
5.3MEDIUM
What is CVE-2026-85588?
phpMyFAQ versions prior to 4.1.8 contain a vulnerability that inadvertently includes live Time-based One-Time Password (TOTP) shared secrets in plaintext within exported user data ZIP files. This flaw allows attackers who gain access to these exported archives to extract the plaintext TOTP seeds, enabling them to generate valid one-time codes. This poses a significant risk, as the attackers can effectively bypass two-factor authentication mechanisms by exploiting this weakness.
Affected Version(s)
phpMyFAQ 0 < 4.1.8
phpMyFAQ 4.1.8
