CVE-2026-27836: phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint
The WebAuthn prepare endpoint (/api/webauthn/prepare) creates new active user accounts without any authentication, CSRF protection, CAPTCHA, or configuration checks. This allows unauthenticated attackers to create unlimited user accounts even when registration is disabled.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27836 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →