logo

Authentication Bypass in the default configuration phpBB

ID: caee5a5c-c403-59d0-9ebd-b63e214a208c

STIX ID: report--caee5a5c-c403-59d0-9ebd-b63e214a208c

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-07-03

Date Updated: 2026-07-24

...
...

phpBB disclosure (CVE-2026-48611): an authentication bypass in the ucp login-link flow allows an attacker to force the 'apache' auth provider and authenticate as any user without a password via a single unauthenticated request; the report provides PoC requests and JS, describes escalation paths to administrator control (and ACP access via founder-group behavior) and RCE on the 4.x extensions catalog, lists detection indicators (auth_provider=apache + mode=login_link), and documents the coordinated disclosure and patch (3.3.17).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.