phpBB released fixes for a critical authentication bypass flaw that lets an unauthenticated attacker obtain a valid session as any user, including administrators, by abusing the login flow and HTTP authentication handling. The issue affects phpBB versions through 3.3.16 and 4.0.0-a2, and stems from trust in the PHP_AUTH_USER value when Apache-based authentication is enabled. Reports describe attackers triggering the vulnerable path with crafted requests using login_link and auth_provider=apache, causing phpBB to treat supplied credentials as authenticated under affected configurations.
Researchers said compromise of an administrator account can lead to remote code execution and full system takeover in current phpBB deployments, turning the authentication flaw into a critical risk. phpBB addressed the bug in 3.3.17 and advised users of 4.0.0-a2 to move to the development master branch because no fixed 4.x release was yet available; public reporting also noted the weakness had existed since 2014 and included proof-of-concept request patterns showing how a forged login could be performed and a session retained.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Aikido publicly disclosed the phpBB vulnerability, describing an unauthenticated one-request login bypass that could lead to remote code execution if an administrator account is compromised. The disclosure noted the issue was exploitable in the default configuration and that some technical details were being temporarily withheld to allow time for patching.
phpBB released version 3.3.17 to fix the authentication bypass issue. Users of 4.0.0-a2 were advised to upgrade to master because no safe 4.x release was yet available.
Aikido reported a critical authentication bypass vulnerability in phpBB to the phpBB maintainers via HackerOne. The report said the flaw affected versions up to and including 3.3.16 and 4.0.0-a2 and could allow unauthenticated access as any user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
aikido.dev
Open sourcephpbb.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.