phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.
References
Configurations
No configuration.
History
28 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9qv9-8xv6-5p35 - |
28 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 16:16
Updated : 2026-05-28 18:56
NVD link : CVE-2026-35676
Mitre link : CVE-2026-35676
CVE.ORG link : CVE-2026-35676
JSON object : View
Products Affected
No product.
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
