CVE-2026-27836

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks. This allows unauthenticated attackers to create unlimited user accounts even when registration is disabled. Version 4.0.18 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*

History

04 Mar 2026, 16:08

Type Values Removed Values Added
CPE cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
First Time Phpmyfaq phpmyfaq
Phpmyfaq
References () https://github.com/thorsten/phpMyFAQ/commit/f2ab673f0668753cd0f7c7c8bc7fd2304dcf5cb1 - () https://github.com/thorsten/phpMyFAQ/commit/f2ab673f0668753cd0f7c7c8bc7fd2304dcf5cb1 - Patch
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-w22q-m2fm-x9f4 - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-w22q-m2fm-x9f4 - Exploit, Vendor Advisory

27 Feb 2026, 20:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 20:21

Updated : 2026-03-04 16:08


NVD link : CVE-2026-27836

Mitre link : CVE-2026-27836

CVE.ORG link : CVE-2026-27836


JSON object : View

Products Affected

phpmyfaq

  • phpmyfaq
CWE
CWE-862

Missing Authorization