CVE-2026-85590 | thorsten phpMyFAQ up to 4.1.7 TOTP remove-twofactor removeTwofactorConfig twofactor_enabled improper authentication

SecurityVulns

A vulnerability, which was classified as critical, has been found in thorsten phpMyFAQ up to 4.1.7. Affected is the function removeTwofactorConfig of the file /api/user/remove-twofactor of the component TOTP. This manipulation of the argument twofactor_enabled causes improper authentication.

The identification of this vulnerability is CVE-2026-85590. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More