MEDIUM
phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export
Published Sep 4, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.53%
Description
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.
Affected products
-
- Version 0StatusaffectedConstraints<4.1.8
- Version 4.1.8StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71011 Advisory
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xhgx-2wj8-g4pj vendor-advisory
- https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-totp-secret-exposure-via-data-export third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71011 | Advisory | |
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xhgx-2wj8-g4pj | vendor-advisory | |
| https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-totp-secret-exposure-via-data-export | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 14, 2026
Reserved Sep 4, 2026
Link CVE-2026-85588
CISA Vulnrichment
Updated Sep 14, 2026
ENISA EUVD
EUVD-2026-71011 Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 14, 2026
Exploited since n/a
Link EUVD-2026-71011