CVE-2026-27836

HIGH

phpmyfaq < 4.0.18 - Unauthenticated Account Creation via WebAuthn Prepare Endpoint

Title source: llm
STIX 2.1

Description

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks. This allows unauthenticated attackers to create unlimited user accounts even when registration is disabled. Version 4.0.18 fixes the issue.

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
phpmyfaq/phpmyfaq < 4.0.18
Published Feb 27, 2026
Tracked Since Feb 28, 2026