logo

Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request

ID: c9a39324-cef2-5d6b-994d-2abe81a7c343

STIX ID: report--c9a39324-cef2-5d6b-994d-2abe81a7c343

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

...
...

A critical authentication bypass (PTT-2026-004, CVSS 9.4) and a chained OAuth CSRF/state-validation flaw (PTT-2026-005, CVSS 8.3) were disclosed in phpBB, enabling unauthenticated attackers to take over arbitrary accounts — including administrators — simply by knowing a username or by delivering a crafted link. The issues affect phpBB up to 3.3.16 (and 4.0.0 alpha), expose private content and user data, and were fixed in phpBB 3.3.17; administrators are advised to patch immediately or disable OAuth logins and audit OAuth account bindings as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.