What does the error mean?
phpMyAdmin is a web tool for managing databases. A database holds your website's data. When you log in, phpMyAdmin checks your user name and password.
The error "Login without a password is forbidden by configuration" shows up when the password box is empty. It can also show up when the database user has no password set. By default, phpMyAdmin does not let anyone in with a blank password. This keeps your data safe.

Fix 1: Type a password
- Open the phpMyAdmin login page.
- Type your user name.
- Type your password in the password box.
- Click Go.
Your browser may have filled the box with nothing. Type it by hand to be sure.
Fix 2: Reset the password
If the user has no password, or you forgot it, set a new one. In cPanel, do this.
- Log in to cPanel.
- Open MySQL Databases.
- Under Current Users, click Change Password for your user.
- Enter a strong password and save.
- Update the password in your website's config file too.
Warning: Your website may stop working until its config file has the new password. Back up the file before you edit it.
Fix 3: Server owners (root access needed)
This part is for VPS and dedicated server owners who run phpMyAdmin themselves. You need root access, which is full control of the server.
- Connect to your server with SSH.
- Open the phpMyAdmin settings file. It is often
/etc/phpmyadmin/config.inc.phporconfig.inc.phpin the phpMyAdmin folder. - Find the line with
AllowNoPassword. - Leave it as
false. This is the safe choice. - Set a password for the MySQL user instead.
AllowNoPassword to true on a live server. Anyone could then enter your database.Still stuck?
Check that your user name is spelled right. Some hosts add a prefix to the user name, like account_user. If it still fails, open a support ticket.
Quick recap
- The error means you tried to log in with an empty password.
- Type the password, or set a new one for the user.
- Update your website's config file after a password change.
- Never allow blank passwords on a live server.