Authentication Bypass in the default configuration phpBB
ID: caee5a5c-c403-59d0-9ebd-b63e214a208c
STIX ID: report--caee5a5c-c403-59d0-9ebd-b63e214a208c
Feed Name: Aikido Security's Blog
phpBB disclosure (CVE-2026-48611): an authentication bypass in the ucp login-link flow allows an attacker to force the 'apache' auth provider and authenticate as any user without a password via a single unauthenticated request; the report provides PoC requests and JS, describes escalation paths to administrator control (and ACP access via founder-group behavior) and RCE on the 4.x extensions catalog, lists detection indicators (auth_provider=apache + mode=login_link), and documents the coordinated disclosure and patch (3.3.17).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
