CVE-2026-76208
HIGHDescription
phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDAP. The state transition is not logged, so administrators cannot detect that the block was overridden. Fixed in 4.1.7.
Is your site exposed to CVE-2026-76208?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-76208? +
How severe is CVE-2026-76208? +
How do I check if I'm vulnerable to CVE-2026-76208? +
Related Vulnerabilities
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs …
Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit …
Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, …
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: …
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent …
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.