Aikido.Dev Critical phpBB Vulnerability Allows Account Hijacking via Single Request
Article Content
- •phpBB vulnerability allows account hijacking with a single unauthenticated request.
- •All versions up to 3.3.16 and 4.0.0-alpha are affected; patch released on June 6, 2026.
- •Attackers can access private messages and forum content, posing significant risks.
A critical vulnerability in phpBB forum software enables attackers to hijack any account, including administrators, with a single unauthenticated request. This flaw, tracked as PTT-2026-004, affects all versions up to 3.3.16 and the 4.0.0-alpha version. Discovered by Dan Stefan Alexandru, it was reported to phpBB on June 4, 2026. The vulnerability is rated 9.4 on the CVSS scale and allows attackers to obtain a valid session for any user by simply knowing their username. The attack is particularly concerning as it exposes private messages and content accessible to the compromised account. Although the Administration Control Panel remains secure, the risk of data exposure is significant. phpBB released a patch (version 3.3.17) on June 6, 2026, urging users to upgrade immediately. A secondary vulnerability, PTT-2026-005, affects OAuth logins and can lead to account takeovers if not mitigated. Administrators are advised to disable OAuth if they cannot upgrade promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Santy and Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…