Inclusion of Sensitive Information in Log Files in phpMyFAQ - CVE-2026-75918

 

Inclusion of Sensitive Information in Log Files in phpMyFAQ - CVE-2026-75918

Published: August 4, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU140879
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-75918
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over accounts.

The vulnerability exists due to insertion of sensitive information into log files in the user tracking feature and password reset handling when logging frontend requests containing password reset query strings to a publicly accessible tracking file. A remote attacker can read the exposed tracking file and replay leaked reset parameters to take over accounts.

User interaction is required because a target user must open a valid password reset link before the leaked reset parameters can be reused.


Affected software

phpMyFAQ

How to mitigate CVE-2026-75918

Install security update from vendor's website.

phpMyFAQ - update to 4.1.7

External References

Related Security Bulletins