logo

phpBB forum fixes auth bypass bug lurking for a decade

ID: 229a33dd-d87b-5d72-8c67-ce08ca1db4e0

STIX ID: report--229a33dd-d87b-5d72-8c67-ce08ca1db4e0

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Bill Toulas

...
...

A decade-old authentication bypass in phpBB (affecting 3.x up to 3.3.16 and 4.0.0-a2) allows trivial account takeover — including administrator accounts — via a single HTTP request; phpBB released a fix in 3.3.17 for the 3.x branch while 4.x remains without a safe release. Exploitation requires no special configuration, could enable full forum administration (view private messages, modify accounts/content), and researchers temporarily withheld technical details to allow admins to patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.