CVE-2026-85590
CVE-2026-85590 is a high-severity vulnerability with a CVSS 4.0 base score of 7.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-308.
Key facts
- Severity: High (CVSS 4.0 base score 7.1)
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-308
- Published:
- Last modified:
Description
phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP without requiring password re-entry or a current TOTP code. The same downgrade is also reachable inline via PUT /api/user/data/update, which accepts a plain twofactor_enabled form field under the same session+CSRF-only guard. An attacker who has hijacked a user's session can silently strip two-factor protection from any account, including administrator accounts, after which password-only authentication succeeds.
Frequently asked questions
- What is CVE-2026-85590?
- phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP without requiring password re-entry or a current TOTP code. The same downgrade is also reachable inline via PUT /api/user/data/update, which accepts a plain twofactor_enabled form field under the same session+CSRF-only guard. An attacker who has hijacked a user's session can silently strip two-factor protection from any account, including administrator accounts, after which password-only authentication succeeds.
- How severe is CVE-2026-85590?
- CVE-2026-85590 has a CVSS 4.0 base score of 7.1, rated high severity.
- Is CVE-2026-85590 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-85590?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-85590 published?
- CVE-2026-85590 was published on 2026-09-04 and last updated on 2026-09-08.
References
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-h96g-59xp-7r5m
- https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-authentication-bypass-via-two-factor-disable
Other CWE-308 vulnerabilities
- CVE-2026-58240 — Critical (CVSS 9.8): SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components…
- CVE-2026-15616 — Critical (CVSS 9.1): Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor…
- CVE-2023-49075 — High (CVSS 8.4): The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition`…
- CVE-2026-67611 — High (CVSS 8.1): OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to…
- CVE-2026-45749 — High (CVSS 8.1): Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST…
- CVE-2025-42959 — High (CVSS 8.1): An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential,…