---
id: CVE-2026-85588
title: >-
  phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext
  within user data export ZIP files
summary: >-
  phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext
  within user data export ZIP files. Attackers obtaining exported archives can
  extract the TOTP seed and generate valid one-time codes to bypass two-factor
  authen…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-200
vendor: thorsten
product: phpMyFAQ
affected:
  - phpMyFAQ < 4.1.8
published: '2026-09-04'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:17:14.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85588'
references:
  - url: >-
      https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xhgx-2wj8-g4pj
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-totp-secret-exposure-via-data-export
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T13:24:41.527941Z'
cvssSource: cna
epss: 0.00375
epssPercentile: 0.31441
ingestedAt: '2026-09-08T20:10:03.164Z'
---

## Overview

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
