CVE-2026-35676
8.2 HIGHphpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attac...
Published: 2026-05-28 · Last updated: 2026-05-28
Severity and scoring
- CVSS
- 8.2 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- CWE
- CWE-640
Description
phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-35676
- [Other]https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9qv9-8xv6-5p35
- [Other]https://www.vulncheck.com/advisories/phpmyfaq-unauthenticated-password-reset-via-user-password-update-endpoint
- [Other]https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9qv9-8xv6-5p35
Related CVEs
Same CWE
- CVE-2026-50635 — LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it (8.8 HIGH)
- CVE-2026-10169 — A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6 (3.7 LOW)
- CVE-2026-7459 — The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account ta... (7.5 HIGH)
- CVE-2026-9609 — A vulnerability was identified in QianFox FoxCMS up to 1.2.6 (4.7 MEDIUM)
- CVE-2026-9466 — A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0 (5.3 MEDIUM)