CVE-2026-76213: phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle

Published Aug 19, 2026
·
Updated

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypass the five-attempt limit by obtaining a fresh session cookie and repeatedly re-authenticating to reset the counter, enabling unbounded TOTP code guessing.

Affected Software

1 affected component
PhpMyFaq phpmyfaq<4.1.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade phpMyFAQ to a version that resolves this vulnerability.

    Fixed in 4.1.7

Event History

Aug 19, 2026
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker needs a valid password for a phpMyFAQ account protected by two-factor authentication. They can then obtain fresh session cookies and re-authenticate after failures to reset the five-attempt TOTP limit.

2

Is this exploitable without valid account credentials?

No. The described attack requires a valid password, although it does not require the attacker to already possess the victim's TOTP code.

3

Which versions are affected?

phpMyFAQ versions before 4.1.7 are affected. Upgrading to 4.1.7 or later addresses the reported issue.

4

How can defenders determine whether attempted exploitation may be occurring?

Review authentication and session activity for repeated successful password re-authentication events followed by failed 2FA attempts, particularly where new session cookies are issued between attempt groups. This pattern may indicate an effort to reset the session-scoped failure counter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203