URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Forum rules
Rules:

Before creating a topic:

If you found a topic concerning your issue, but it does not answer your question or resolve your issue, do not attempt to bump or hijack it. Rather create a new topic with a reference link to the topic in question.

Choosing a topic title:

Choose a topic title that makes sense with what the thread you made is about. Don't create topic titles that contain spam, sexual, or racial comments or subjects.

Topic Content:

Stay on topic. Don't create topics that have nothing to do with the forum they are in. Also, don't go off-topic in already-created topics. No one wants to hear you talk about your weekend in the clan news section. Off-topic chat is exempt from the off-topic rule unless it gets way too far out of hand. Lastly, no flaming, spam, sexual, or racial messages.

Other things to keep in mind:

When making a new topic, make sure that you use correct grammar and spelling so that the person replying to you will know what you are talking about. Proofread your post before you press the reply button so that you know you did not make any mistakes while you were typing. Make sure to try not to use profanity as well unless appropriate to the subject. Lastly, USE COMMON SENSE. I don't know how many times I've seen senseless posts because people haven't taken a moment to think before acting.
Locked
User avatar
202Green-X
Co-Leader
Posts: 1
Joined: October 7th, 2007, 11:29 am
Location: New Mexico U.S.A.
Contact:

URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by 202Green-X »

You need to update your board to phpBB 3.3.17 immediately. ALL versions from 3.1.0 to 3.3.16 (which covers over 10 years of phpBB releases) contain a critical vulnerability CVE-2026-48611.

The Reality of the Vulnerability
The official phpBB developers handled this disclosure extremely poorly. In their 3.3.17 release announcement, they buried this catastrophic flaw in the middle of normal text as if it were a minor bug: "Furthermore, two separate improper checks in the previous OAuth implementation could have been used to hijack user accounts."

Do not let that wording fool you. In reality, this vulnerability allows ANY UNAUTHENTICATED ATTACKER to log in as ANY USER on the forum, without any extra checks.

There is no complex setup required. The exploit is literally a single URL query. An attacker can use a 1-line curl command and instantly receive valid cookies to authenticate as any user they choose.

All an attacker needs to know is a target's username, which is trivially easy to find on 99% of forums. They will target moderator and admin accounts. Here is what that actually means for your board:
  • Attackers get full access to everything the hijacked user has, including reading all Private Messages (DMs).
  • By logging in as an admin or moderator, they gain full access to the Moderator Control Panel (MCP).
  • From the MCP, the attacker can check all moderation logs, delete threads, ban users, and expose the private email addresses of every user on your forum.
Exploits Are Trivial to Create
Security researchers at Aikido are holding back technical details, but that does not keep you safe. Because the exploit is so simple, anyone with an LLM can trivially analyze the 3.3.17 patchset, identify the exact flaw in 5-10 minutes, and have a working Proof of Concept (PoC) ready to go.

Aikido privately notified a handful of the largest online communities, but THOUSANDS of popular phpBB forums are still vulnerable right now because they haven't gotten the news.

Do not wait for someone to target your board. UPDATE TO 3.3.17 NOW.
Image -202Green
Locked

Who is online

Users browsing this forum: No registered users and 0 guests