CVE-2026-85591: phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change

Published Sep 4, 2026
·
Updated

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to the user data update endpoint with only a CSRF token to silently change any user's password, including administrators, causing irreversible account takeover and victim lockout.

Affected Software

1 affected component
phpMyFAQ<4.1.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade phpMyFAQ to a version that resolves this vulnerability.

    Fixed in 4.1.8
  2. Upgrade

    Upgrade phpMyFAQ to a version that resolves this vulnerability.

    Fixed in 4.1.8Patch Authentication Bypass via Unverified Password Change

Event History

Sep 4, 2026
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionWeakness

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

The attacker must be authenticated and have session access. Exploitation also requires a valid CSRF token for the user data update request.

2

Which accounts can be taken over?

An authenticated attacker can change the password of any user account, including administrator accounts. This can lock the legitimate user out and result in account takeover.

3

How can I tell whether my deployment is affected?

Deployments running phpMyFAQ versions before 4.1.8 are affected. The vulnerable behavior is in the user control panel API password-change functionality, which accepts a PUT request without verifying the current password.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203