MEDIUM 5.3 NVD
CVE-2026-85588
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extrac
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.
References
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xhgx-2wj8-g4pj
- https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-totp-secret-exposure-via-data-e
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.