Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request
ID: c9a39324-cef2-5d6b-994d-2abe81a7c343
STIX ID: report--c9a39324-cef2-5d6b-994d-2abe81a7c343
Feed Name: Infosecurity Magazine (News)
A critical authentication bypass (PTT-2026-004, CVSS 9.4) and a chained OAuth CSRF/state-validation flaw (PTT-2026-005, CVSS 8.3) were disclosed in phpBB, enabling unauthenticated attackers to take over arbitrary accounts — including administrators — simply by knowing a username or by delivering a crafted link. The issues affect phpBB up to 3.3.16 (and 4.0.0 alpha), expose private content and user data, and were fixed in phpBB 3.3.17; administrators are advised to patch immediately or disable OAuth logins and audit OAuth account bindings as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
