CVE-2026-27836 | thorsten phpmyfaq up to 4.0.17 WebAuthn Prepare Endpoint /api/webauthn/prepare authorization (GHSA-w22q-m2fm-x9f4 / EUVD-2026-9059)
A vulnerability classified as problematic has been found in thorsten phpmyfaq up to 4.0.17. Affected is an unknown function of the file /api/webauthn/prepare of the component WebAuthn Prepare Endpoint. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-27836. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.