Medium severityNVD Advisory· Published Sep 4, 2026
CVE-2026-85588
CVE-2026-85588
Description
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.1.8
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.