CVE-2026-46364Patch

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-05-15); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Mentions · 2026-05-19: 1Mentions · 2026-05-30: 1Mentions · 2026-06-11: 1PoC Mentioned / Linked · 2026-05-30: 1PoC Mentioned / Linked · 2026-06-11: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-16: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-11: 105-1505-1605-1905-3006-11
Signal classification3 categories
Patch
240.0%
Disclosure
240.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-151
Patch1
2026-05-161
Patch1
2026-05-191
Disclosure1
2026-05-301
PoC1
2026-06-111
Disclosure1
Full discourse5 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-46364 (CVSS 9.8): Unauthenticated SQL injection via malicious User-Agent on /api/captcha 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJwaHBNeUZBUSI%3D 🎯1.2K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="phpMyFAQ" 🔖Refer: https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-289f-fq7w-6q2w #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    A disclosure of CVE-2026-46364, an unauthenticated SQL injection in phpMyFAQ, is presented along with FOFA search results and a vendor advisory link indicating a fix is available.

    123075335.9K
    14.4K followersView on X
  • 0x0smilex@0x0smilex
    PoC

    We are so back 🔥.Built a PoC for CVE-2026-46364 as part of security research, with Claude AI assisting in analysis and validation🤯. Only For Educational Purposes. #claude #bugbounty #bugbountytip #ethicalhacking #cve #Trending #vibecoding https://t.co/g607OUZJVe

    Post summary

    The author announces having built a Proof‑of‑Concept for CVE‑2026‑46364 for educational purposes, with no exploit code, patch discussion, or evidence of active exploitation.

    1002341.2K
    2.2K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-46364 - critical 🚨 phpMyFAQ <= 4.1.1 - SQL Injection > phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in Buil... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-46364 @pdnuclei #NucleiTemplates #cve

    Post summary

    A new critical unauthenticated SQL injection vulnerability (CVE‑2026‑46364) in phpMyFAQ 4.1.1 and earlier is disclosed, with a detection template link provided, but no patches, active exploitation, or exploit code is referenced.

    0002198
    958 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Multiple phpMyFAQ Vulnerabilities (CVE-2026-46364, CVE-2026-45010) phpMyFAQ contains critical vulnerabilities that may allow unauthenticated attackers to perform SQL injection through crafted User-Agent headers and brute-force TOTP authentication codes via the /admin/check endpoint. Successful exploitation could lead to credential disclosure and full administrative account takeover. 👉 Affected: phpMyFAQ < 4.1.2 | Fix: Upgrade to 4.1.2

    Post summary

    The text announces critical PHPMyFAQ vulnerabilities and explicitly recommends upgrading to version 4.1.2 as the remediation.

    00020121
    255 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-46364 — CVSS 9.8/10 ██████████ phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/WuFLhBLChE

    Post summary

    The tweet announces CVE-2026-46364, a critical unauthenticated SQL injection in phpMyFAQ before v4.1.2, and urges users to apply the available patch.

    10000107
    42 followersView on X

Explore more