phpBB has fixed a long-standing authentication bypass vulnerability that lets attackers log in as any forum user, including administrators, with a single HTTP request. The flaw, discovered by Aikido and reported through phpBB’s HackerOne disclosure program, affects phpBB 3.3.16 and earlier as well as 4.0.0-a2, spans both the 3.x and 4.x branches, and reportedly existed for about 10 years. Researchers said the bug requires no special configuration and can be exploited against default deployments.
Successful exploitation could allow attackers to read private messages, manipulate forum content and user accounts, impersonate moderators or administrators, and deface forums. phpBB released a fix for the 3.x branch in version 3.3.17, while no patched 4.x release was available at the time of reporting. Aikido withheld technical details to give administrators time to update and separately warned operators of large phpBB forums; researchers also noted that remote code execution is not possible because the Admin Control Panel enforces a separate password check.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Aikido disclosed a roughly 10-year-old phpBB authentication bypass affecting versions 3.3.16 and earlier and 4.0.0-a2. The researchers said exploitation requires no special configuration and works against default deployments, but withheld technical details while warning large forum operators directly.
phpBB released version 3.3.17 to patch the authentication bypass vulnerability in the 3.x branch. At the time of reporting, no fix was yet available for the affected 4.x branch.
Aikido published a technical write-up for CVE-2026-48611 explaining that phpBB's login-link flow could be abused by selecting the apache auth provider, enabling login as any user with a single request. The post included proof-of-concept requests and advised defenders to review logs for suspicious mode=login_link and auth_provider=apache combinations, including POST-overrides-GET variants.
phpBB received Aikido's report of a long-standing authentication bypass vulnerability through its HackerOne vulnerability disclosure program. The flaw allows login as any forum user, including administrators, with a single HTTP request.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcexakep.ru
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceaikido.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.