LOWVulnerability

CVE-2026-85588

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.

Properties

cve_id
CVE-2026-85588
signal_observed_at
2026-09-16T01:21:39+00:00
published_at
2026-09-04T12:17:21.013
last_modified
2026-09-14T14:17:14.910

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85588 — Ninja Signal Threat Intelligence | Ninja Signal