Junglewise Threat Intelligence

CVE-2026-85590: phpMyFAQ two-factor authentication bypass via insufficient re-authentication

CVE-2026-85590 · Severity: info · CVSS 7.1 · Published 2026-09-04

Technologies: Thorsten phpMyFAQ. Vendors: Thorsten.

Executive brief

phpMyFAQ is a popular open-source FAQ management system used to manage knowledge bases and frequently-asked-question repositories. An attacker who gains access to a user's browser session can permanently disable the account's two-factor authentication without requiring a password or current authentication code, converting any session hijacking into permanent account takeover—including for administrative accounts. After disabling two-factor protection, password-only login succeeds.

Technical details

The vulnerability is an authentication bypass in the two-factor authentication disable functionality, rooted in CWE-308 (Use of Single-factor Authentication). The removeTwofactorConfig() API endpoint (POST /api/user/remove-twofactor) and the inline twofactor_enabled form field in PUT /api/user/data/update both check only for an active session and valid CSRF token—they do not require password re-entry, current TOTP code, or any step-up authentication. An attacker with session hijacking (e.g., via XSS or session theft) can send a single request with a harvested CSRF token to strip 2FA protection from any account. The vulnerability affects phpMyFAQ versions before 4.1.8 and has been patched in version 4.1.8. Attack vector is network-based with low complexity and requires only low privileges (an authenticated session).

Affected products

  • thorsten phpMyFAQ before 4.1.8

Timeline

  • 2026-08-20: disclosed: Vulnerability reported via GitHub Security Advisory
  • 2026-09-04: advisory: Public disclosure and CVE publication
  • 2026-09-04: patched: Patched in version 4.1.8

References

Related threats