PT-2026-22389 · Phpmyfaq · Phpmyfaq

Offensive-Ai

·

Published

2026-02-27

·

Updated

2026-03-04

·

CVE-2026-27836

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.0.18
Description The WebAuthn prepare endpoint, /api/webauthn/prepare, in versions prior to 4.0.18 lacks authentication, CSRF protection, captcha, or configuration checks. This allows unauthenticated attackers to create an unlimited number of user accounts, even when registration is disabled. The vulnerable parameter is not specified.
Recommendations Update to version 4.0.18 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-27836
GHSA-W22Q-M2FM-X9F4

Affected Products

Phpmyfaq