SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75918

HIGH · CVSS 8.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

phpMyFAQ versions prior to 4.1.7 are vulnerable due to the storage of password reset tokens in a publicly accessible tracking file when user tracking is enabled. This flaw allows unauthenticated attackers to access the tracking file and extract tokens, enabling them to exploit the password reset functionality and potentially take over user accounts. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized account access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75918
Severity
HIGH
CVSS
8.8
EPSS
0.34%

Original NVD Description

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts.

Related CVEs

Other vulnerabilities affecting the same vendor(s)