Improper Authentication in phpMyFAQ - CVE-2026-56737
Published: July 14, 2026
phpMyFAQ
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and take over accounts.
The vulnerability exists due to improper authentication in the public two-factor verification endpoint `/check` when handling crafted authentication requests with an attacker-chosen `user-id` and TOTP token. A remote attacker can send a specially crafted request to bypass authentication and take over accounts.
Only accounts with two-factor authentication enabled are affected, and a valid password is not required for the affected login flow.