


Perceptive Security
SOC/SIEM Consultancy

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to cre…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 19:09:38
Source:
nvd.nist.gov
Web Technologies
phpMyFAQ versions before 4.1.3 contain an authentication bypass vulnerability in API v4.0. The vulnerability stems from a default empty api.apiClientToken configuration that allows unauthenticated users to bypass authentication. Attackers can exploit this by sending requests with an empty x-pmf-token header to bypass token validation. This enables unauthorized creation and modification of FAQ entries through vulnerable POST endpoints. The affected endpoints include /api/v4.0/faq/create, /api/v4.0/category, and /api/v4.0/question. Attackers can inject malicious content into the application through these endpoints.
Technical details
Mitigation steps:
Affected products:
phpMyFAQ
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35672
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-gp95-j463-vv28
https://www.vulncheck.com/advisories/phpmyfaq-authentication-bypass-via-empty-api-token
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
