CVE-2026-76207
CVE-2026-76207 is a high-severity vulnerability in Phpmyfaq with a CVSS 3.x base score of 8.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-304.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- CVSS v4: 8.6
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-304
- Affected product: Phpmyfaq
- Published:
- Last modified:
Description
phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.
Frequently asked questions
- What is CVE-2026-76207?
- phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.
- How severe is CVE-2026-76207?
- CVE-2026-76207 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-76207 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-76207?
- CVE-2026-76207 affects Phpmyfaq. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-76207?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-76207 published?
- CVE-2026-76207 was published on 2026-08-19 and last updated on 2026-09-01.
References
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-hvj7-4fmg-53cr
- https://www.vulncheck.com/advisories/phpmyfaq-before-2fa-bypass-via-remember-me-cookie
Affected products (1)
- cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
More vulnerabilities in Phpmyfaq
- CVE-2023-5865 — Critical (CVSS 9.8): Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
- CVE-2023-5227 — Critical (CVSS 9.8): Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- CVE-2023-4006 — Critical (CVSS 9.8): Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
- CVE-2023-2429 — Critical (CVSS 9.8): Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
- CVE-2023-0311 — Critical (CVSS 9.8): Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2023-0307 — Critical (CVSS 9.8): Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
Other CWE-304 vulnerabilities
- CVE-2023-54391 — Critical (CVSS 9.8): Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in…
- CVE-2024-8954 — Critical (CVSS 9.8): In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the…
- CVE-2024-2172 — Critical (CVSS 9.8): The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to…
- CVE-2026-94052 — Critical (CVSS 9.1): A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or…
- CVE-2026-59564 — Critical (CVSS 9.1): An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and…
- CVE-2026-61466 — Critical (CVSS 9.1): In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope`…