Home

Description

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks. This allows unauthenticated attackers to create unlimited user accounts even when registration is disabled. Version 4.0.18 fixes the issue.

PUBLISHED Reserved 2026-02-24 | Published 2026-02-27 | Updated 2026-03-03 | Assigner GitHub_M




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Problem types

CWE-862: Missing Authorization

Product status

< 4.0.18
affected

References

github.com/...pMyFAQ/security/advisories/GHSA-w22q-m2fm-x9f4

github.com/...ommit/f2ab673f0668753cd0f7c7c8bc7fd2304dcf5cb1

cve.org (CVE-2026-27836)

nvd.nist.gov (CVE-2026-27836)

Download JSON