What is CVE-2026-76213?
CVE-2026-76213 is a brute-force vulnerability in phpMyFAQ versions before 4.1.7 affecting the two-factor authentication step, where the failure counter is session-scoped and resets upon successful password re-authentication. Attackers with a valid password can bypass the five-attempt limit by obtaining a new session cookie. Users should update to version 4.1.7 immediately.
Azərbaycanca: CVE-2026-76213 phpMyFAQ-un 4.1.7 versiyasından əvvəlki versiyalarında iki faktorlu autentifikasiya mərhələsində brute-force zəifliyi aşkarlanıb, burada uğursuzluq sayğacı sessiya əsaslıdır və uğurlu parol yenidən autentifikasiyası ilə sıfırlanır. Bu, etibarlı parola malik təcavüzkarın yeni sessiya çərəzi əldə etməklə beş cəhd limitini keçməsinə imkan verir. phpMyFAQ istifadəçiləri dərhal 4.1.7 versiyasına yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
How does CVE-2026-76213 allow bypassing two-factor authentication in phpMyFAQ?
Since the failure counter is session-scoped, an attacker with a valid password can obtain a new session cookie through successful password re-authentication, resetting the five-attempt limit and continuing the brute-force attack on the two-factor authentication step.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.