Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56737— phpMyFAQ's two-factor authentication login bypasses the password factor

Quick assessment

Affected
thorsten phpMyFAQ
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

phpMyFAQ 是一款开源的常见问题解答(FAQ)Web 应用程序。版本 3.2.0 至 4.1.5 在其公开的二次认证(2FA)验证流程中存在身份认证绕过漏洞:攻击者无需先使用账户密码进行身份认证,只需提交该账户的数值型用户 ID 和一个有效或暴力破解得到的六位数 TOTP 验证码,即可接管任何启用了二次认证的账户,包括管理员账户。版本 4.1.6 已通过将 TOTP 验证绑定到成功通过密码认证后建立的会话,并限制 TOTP 验证失败次数的方式修复了此漏洞。目前尚无官方临时解决方案;受影响的部署应升级至 4.1

CVSS 8.1 · High EPSS 0.40% · P32

Affected Version Matrix 1

VendorProduct Version RangeStatus
thorsten phpMyFAQ >= 3.2.0, < 4.1.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56737

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
phpMyFAQ's two-factor authentication login bypasses the password factor
Source: CVE Program / CVE List V5
Vulnerability Description
phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID and a valid or brute-forced six-digit TOTP code without first authenticating with the account password, allowing takeover of any 2FA-enabled account, including administrator accounts. Version 4.1.6 is patched by binding TOTP verification to a session established after successful password authentication and limiting failed TOTP attempts. No official workaround is documented; affected installations should upgrade to 4.1.6 or later.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
thorsten phpMyFAQ >= 3.2.0, < 4.1.6 -

II. Public POCs for CVE-2026-56737

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56737

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-56737 (2)

Vendor Advisories for CVE-2026-56737 (1)

Same Patch Batch · thorsten · 2026-09-24 · 4 CVEs total

CVE-2026-56738 8.5 HIGH phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
CVE-2026-56736 8.2 HIGH phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submiss
CVE-2026-47132 5.4 MEDIUM phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumer

IV. Related Vulnerabilities

V. Comments for CVE-2026-56737

No comments yet


Leave a comment