logo

10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums

ID: 8816534f-e276-555a-b347-202ce7331e62

STIX ID: report--8816534f-e276-555a-b347-202ce7331e62

Feed Name: Aikido Security's Blog

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-07-24

...
...

A critical authentication bypass in phpBB (affecting versions up to 3.3.16 and 4.0.0-a2) allows an unauthenticated attacker to obtain a valid session as any user — including administrators — enabling account impersonation and potential data exposure; phpBB released a patch in 3.3.17 on 2026-06-06 and coordinated disclosure is ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.