Aikido.Dev
Critical phpBB Vulnerability Allows Account Hijacking via Single Request
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in phpBB forum software enables attackers to hijack any account, including administrators, with a single unauthenticated request. This flaw, tracked as PTT-2026-004, affects all versions up to 3.3.16 and the 4.0.0-alpha version. Discovered by Dan Stefan Alexandru, it was reported to phpBB on June 4, 2026. The vulnerability is rated 9.4 on the CVSS scale and allows attackers to obtain a valid session for any user by simply knowing their username. The attack is particularly concerning as it exposes private messages and content accessible to the compromised account. Although the Administration Control Panel remains secure, the risk of data exposure is significant. phpBB released a patch (version 3.3.17) on June 6, 2026, urging users to upgrade immediately. A secondary vulnerability, PTT-2026-005, affects OAuth logins and can lead to account takeovers if not mitigated. Administrators are advised to disable OAuth if they cannot upgrade promptly.
Key Points: • phpBB vulnerability allows account hijacking with a single unauthenticated request. • All versions up to 3.3.16 and 4.0.0-alpha are affected; patch released on June 6, 2026. • Attackers can access private messages and forum content, posing significant risks.