CVE-2026-56737

HIGH CVSS 3.1: 8.1 EPSS 0.40%
Updated Sep 29, 2026
phpMyFAQ
Parameter Value
CVSS 8.1 (HIGH)
Affected Versions 3.2.0 — 4.1.5
Fixed In 4.1.6
Type CWE-287 (Improper Authentication)
Vendor phpMyFAQ
Public PoC No

phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID and a valid or brute-forced six-digit TOTP code without first authenticating with the account password, allowing takeover of any 2FA-enabled account, including administrator accounts. Version 4.1.6 is patched by binding TOTP verification to a session established after successful password authentication and limiting failed TOTP attempts.

No official workaround is documented; affected installations should upgrade to 4.1.6 or later.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1