VYPR
Vypr IntelligenceAI-generatedAug 19, 2026· 14 CVEs

PhpMyFAQ: 14 Vulnerabilities Including Auth Bypass Patched in Single Disclosure

PhpMyFAQ: 14 vulnerabilities disclosed, including critical authentication bypass and 2FA flaws, patched in 4.1.7.

Key findings

  • 14 PhpMyFAQ vulnerabilities disclosed on August 19, 2026, patched in version 4.1.7.
  • High-severity flaws include authentication bypass and 2FA circumvention.
  • Vulnerabilities span data exposure, SQL injection, and insecure file handling.
  • Users must update to 4.1.7 to mitigate risks.

On August 19, 2026, a batch of 14 vulnerabilities was disclosed for PhpMyFAQ, impacting versions prior to 4.1.7 and 4.1.6. These vulnerabilities, ranging in severity from medium to high, expose various weaknesses in authentication, data handling, and configuration management. The disclosures highlight critical security flaws that could allow unauthenticated attackers to access sensitive information, bypass security measures, and potentially take over user accounts.

Several vulnerabilities revolve around authentication bypass and weaknesses in multi-factor authentication (MFA) mechanisms. CVE-2026-76208, a high-severity flaw, allows authentication bypass when LDAP is enabled by unconditionally activating accounts after a successful LDAP bind, overwriting local account statuses. CVE-2026-76213 and CVE-2026-76207, both high-severity, detail bypasses in the two-factor authentication process. The former exploits a session-scoped failure counter that resets on successful password re-authentication, while the latter involves the issuance of remember-me tokens before 2FA completion, allowing attackers to skip the second factor. Additionally, CVE-2026-75919, another high-severity vulnerability, permits unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled by exploiting the SetupController.

Data exposure and unauthorized access are also significant concerns within this batch. CVE-2026-76215 (Medium) allows unauthenticated attackers to retrieve restricted comment text, commenter email addresses, and attachment filenames by failing to apply parent FAQ visibility checks. CVE-2026-76211 (Medium) permits any authenticated user to access sensitive administrative data, including LDAP server details and bind account information, due to a lack of permission enforcement on configuration read endpoints. Furthermore, CVE-2026-76206 (Medium) enables unauthenticated attackers to retrieve draft FAQ metadata, such as titles and author names, by exploiting the PDF export endpoint's failure to validate active status.

Other notable vulnerabilities include a SQL injection flaw (CVE-2026-76205, High) in the glossary endpoints, where authenticated users can craft payloads to escape SQL literals. CVE-2026-76212 (Medium) describes an incorrect LIKE ESCAPE character in the PostgreSQL backend, rendering wildcard escaping ineffective. CVE-2026-75920 (Medium) involves the insecure writing of content backup ZIP archives to the web-accessible document root, potentially exposing sensitive files like database credentials. Finally, CVE-2026-75918 (High) stores password reset tokens in a publicly accessible tracking file, allowing unauthenticated attackers to intercept and reuse these tokens.

All 14 vulnerabilities were fixed in PhpMyFAQ version 4.1.7, with some earlier versions (prior to 4.1.6) also addressed by earlier patches. Users are strongly advised to update to the latest version to mitigate these security risks. The extensive nature of this batch underscores the importance of regular security audits and timely patching for web applications.

The timely disclosure and patching of these vulnerabilities are crucial for protecting user data and maintaining the integrity of systems utilizing PhpMyFAQ. Users should prioritize updating their installations to version 4.1.7 to address the full scope of issues reported in this coordinated disclosure.

The vulnerabilities patched in this batch include:

Users should update to PhpMyFAQ 4.1.7 to address all disclosed vulnerabilities.

The batch of 14 vulnerabilities disclosed on August 19, 2026, for PhpMyFAQ highlights significant security weaknesses across authentication, data handling, and configuration. The most severe issues include high-severity flaws enabling authentication bypass and two-factor authentication circumvention. All identified vulnerabilities have been addressed in version 4.1.7.

The broad range of issues, from SQL injection to information disclosure and insecure file handling, emphasizes the need for prompt updates. The vendor has released version 4.1.7 to patch all these CVEs.

The disclosed vulnerabilities include:

PhpMyFAQ version 4.1.7 resolves all these security issues.

PhpMyFAQ users are urged to update to version 4.1.7 immediately following the coordinated disclosure of 14 vulnerabilities on August 19, 2026. The vulnerabilities span critical areas including authentication bypass, two-factor authentication weaknesses, and information disclosure. The most severe flaws, rated as High, allow for unauthenticated access and account takeover. All issues are addressed in version 4.1.7.

The patched vulnerabilities include:

Updating to version 4.1.7 is essential for security.

On August 19, 2026, a significant batch of 14 vulnerabilities affecting PhpMyFAQ versions prior to 4.1.7 and 4.1.6 was disclosed. These vulnerabilities range from medium to high severity, with several critical flaws allowing for authentication bypass, two-factor authentication circumvention, and unauthorized access to sensitive data. All issues have been patched in version 4.1.7.

The vulnerabilities include:

Users are strongly recommended to update to PhpMyFAQ 4.1.7 to secure their installations.

A coordinated disclosure on August 19, 2026, revealed 14 vulnerabilities in PhpMyFAQ, impacting versions prior to 4.1.7 and 4.1.6. The vulnerabilities, rated from medium to high severity, include critical flaws in authentication mechanisms, data exposure, and configuration management. All identified issues are resolved in version 4.1.7.

Key vulnerabilities patched include:

PhpMyFAQ users must update to version 4.1.7 to protect against these security risks.

On August 19, 2026, a batch of 14 vulnerabilities affecting PhpMyFAQ versions prior to 4.1.7 and 4.1.6 was disclosed. These vulnerabilities, ranging in severity from medium to high, include critical flaws that could allow for authentication bypass, two-factor authentication circumvention, and unauthorized access to sensitive data. All identified issues have been patched in version 4.1.7.

The patched vulnerabilities include:

Users are strongly advised to update to PhpMyFAQ 4.1.7 to mitigate these security risks.

AI-written article. Grounded in 14 CVE records listed below.