MEDIUMVulnerability

CVE-2026-76209

phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can bypass the registration restriction by submitting requests to POST /api/register or POST /api/v3.1/register endpoints, which do not check the configuration flag enforced by the HTML registration page.

Properties

severity
MEDIUM
score
4.3
epss_score
0.00241
cve_id
CVE-2026-76209
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-08-19T14:17:46.370
last_modified
2026-09-01T15:21:54.990
epss_percentile
0.15161

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76209 — Ninja Signal Threat Intelligence | Ninja Signal