Vulnerability Description
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.
Related Weaknesses (CWE)
References
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xhgx-2wj8-g4pj
- https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-totp-secret-exposure-
FAQ
What is CVE-2026-85588?
CVE-2026-85588 is a documented vulnerability. phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-t...
How severe is CVE-2026-85588?
CVSS scoring is not yet available for CVE-2026-85588. Check NVD for updates.
Is there a patch for CVE-2026-85588?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.