CVE-2026-35676

phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.
Configurations

No configuration.

History

28 May 2026, 17:16

Type Values Removed Values Added
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9qv9-8xv6-5p35 - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9qv9-8xv6-5p35 -

28 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 16:16

Updated : 2026-05-28 18:56


NVD link : CVE-2026-35676

Mitre link : CVE-2026-35676

CVE.ORG link : CVE-2026-35676


JSON object : View

Products Affected

No product.

CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password