CVE-2026-85591
phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to the user data update endpoint with only a CSRF token to silently change any user's password, including administrators, causing irreversible account takeover and victim lockout.
| CWE | CWE-620 |
| Vendor | thorsten |
| Product | phpmyfaq |
| Published | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for thorsten phpmyfaq
Be the first to know when new unknown vulnerabilities affecting thorsten phpmyfaq are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
thorsten / phpMyFAQ
0 < 4.1.8
References
Credits
๐ skeletonsec