CVE-2026-35676
phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
28 may 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
thorsten · phpMyFAQ¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →