Threat reportVulnerabilityTL-2026-0789

phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17

criticalPATCHED

phpBB Authentication Bypass and OAuth Account Takeover (TL-2026-0789), also tracked as PTT-2026-004, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-06-14. It has no confirmed attribution, affects phpBB phpBB (3.x branch), references 2 CVEs (CVE-2026-48611, CVE-2026-48612), maps to 17 MITRE ATT&CK techniques (T1078, T1087, T1098), and is covered by 9 detection rules and 19 indicators of compromise.

CVSS
9.4/10Critical
CVEs
2Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-0789

Threat ID
TL-2026-0789
Also known as
PTT-2026-004, PTT-2026-005, phpBB decade-old auth bypass, phpBB silent account hijack
Severity
CRITICAL
CVSS
9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
online-communities, technology, media, gaming, education
Target regions
Global
Detection rules
9
Indicators of compromise
19

How phpBB Authentication Bypass and OAuth Account Takeover works

A critical authentication bypass in phpBB (CVE-2026-48611, CVSS 9.4) let an unauthenticated attacker obtain a valid session as any active user — including administrators — with a single crafted HTTP request, requiring no password, prior access, or victim interaction, in the default database-authentication configuration. A companion OAuth account-takeover flaw (CVE-2026-48612, CVSS 8.3) silently links an attacker's credentials to a victim account via CSRF. Both were patched in phpBB 3.3.17 on June 6, 2026.

phpBB is one of the most widely deployed open-source PHP bulletin-board (forum) platforms, powering thousands of community forums and, per Pentest-Tools.com, tens of millions of users worldwide. In June 2026 two vulnerabilities were disclosed, tracked by the reporting researchers as PTT-2026-004 and PTT-2026-005 and later assigned CVE-2026-48611 and CVE-2026-48612.

PTT-2026-004 / CVE-2026-48611 is a critical authentication bypass (CVSS 9.4, CWE-305 Authentication Bypass by Primary Weakness) present in the phpBB codebase for roughly a decade (reporting traces the flawed logic to the 2014 era). A single unauthenticated HTTP request is sufficient to be handed a valid authenticated session as any chosen active account, including administrators. The attack requires no password, no special configuration, and no action by the victim, and is exploitable in the stock default configuration (auth_method=db). Because phpBB member lists are typically public, an attacker only needs a target username to take over the account. The vulnerability does NOT directly yield remote code execution: a separate password check guards the Admin Control Panel (ACP) and is not bypassed by this flaw. However, a hijacked administrator or moderator session still permits reading private messages and restricted forums, creating/modifying/deleting content and user accounts, impersonating staff, and defacing the board.

PTT-2026-005 / CVE-2026-48612 is a high-severity OAuth account-takeover weakness (CVSS 8.3, CWE-352 Cross-Site Request Forgery combined with missing OAuth state validation). It affects only boards where an administrator has enabled OAuth login with a supported provider (Google, Facebook, or Bitly) — a non-default configuration. By embedding a malicious link (for example inside an <img src="..."> tag in a forum post or private message) the attacker forces an authenticated victim's browser to silently bind the attacker's OAuth identity to the victim's account, granting the attacker persistent login access without any visible user interaction.

The flaws were discovered by Dan Stefan Alexandru of Pentest-Tools.com on May 13, 2026 and reported to the phpBB security team via its HackerOne Vulnerability Disclosure Program; phpBB triaged the report within minutes and shipped phpBB 3.3.17 ("Young Bertie"), a maintenance and security release fixing four security issues (one critical), on June 6, 2026, with public disclosure on June 8, 2026. The 3.x branch is fixed in 3.3.17; at disclosure time the 4.x branch (4.0.0-a2 and earlier) had no safe stable release and administrators were directed to the master branch. The 3.3.17 update relocates the OAuth redirect URI (to a path under /user/oauth/authenticate/...), which can break previously configured OAuth provider redirects until re-registered. As of disclosure no CISA KEV listing, no EPSS score, no public proof-of-concept, and no confirmed in-the-wild exploitation had been reported; the researchers withheld root-cause technical details to give administrators time to patch. NOTE: some early reporting (BleepingComputer / an Aikido write-up) credited the discovery to Aikido and cited a June 2 HackerOne timeline; the CVE-assigning technical advisory attributes discovery to Dan Stefan Alexandru of Pentest-Tools.com — both attributions are recorded in the timeline below.

MITRE ATT&CK techniques used in TL-2026-0789

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Discovery

T1087 Account Discovery

Persistence

T1098 Account Manipulation; T1136 Create Account

Collection

T1185 Browser Session Hijacking; T1213 Data from Information Repositories

Credential Access

T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie; T1556 Modify Authentication Process

Impact

T1491 Defacement; T1565 Data Manipulation

Lateral Movement

T1534 Internal Spearphishing

lateral-movement

T1550 Use Alternate Authentication Material

Reconnaissance

T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains

Affected products and versions in phpBB Authentication Bypass and OAuth Account Takeover

  • phpBB — phpBB (3.x branch)
    Vulnerable versions: <= 3.3.16
    Fixed in: 3.3.17
  • phpBB — phpBB (4.x branch)
    Vulnerable versions: <= 4.0.0-a2
    Fixed in: master branch (no stable 4.x release at disclosure)

Remediation for phpBB Authentication Bypass and OAuth Account Takeover

Patches

  • phpBB 3.3.17 ("Young Bertie"), released 2026-06-06 — fixes four security issues including the critical authentication bypass.
  • phpBB 4.x: apply the patched master branch (no safe stable 4.x release at disclosure).

Immediate actions

  • Upgrade phpBB 3.x boards to 3.3.17 or later immediately — this fixes both CVE-2026-48611 and CVE-2026-48612.
  • For 4.x boards (4.0.0-a2 and earlier) with no safe stable release, update to the patched master branch per phpBB guidance.
  • As an interim mitigation for the OAuth flaw, disable OAuth authentication and revert to database authentication.
  • Audit the OAuth account-link records for unexpected or recently added provider bindings on privileged (admin/moderator) accounts and unlink any that are suspicious.

Workarounds

  • Disable OAuth login and use database authentication only (mitigates CVE-2026-48612).
  • Place the board behind a WAF rule alerting on anomalous authentication/session-grant responses while patching is scheduled.

Longer-term hardening

  • After upgrading, re-register OAuth provider redirect URIs to the new /user/oauth/authenticate/... path, since 3.3.17 relocates the OAuth redirect URI and may break existing provider configs.
  • Reset administrator and moderator credentials and invalidate active sessions on any board that was running a vulnerable version and reachable from the internet.
  • Restrict or remove public member lists where feasible to raise the bar on target enumeration.
  • Subscribe to phpBB security announcements and establish a routine patch cadence for the forum and its extensions.

CVEs associated with phpBB Authentication Bypass and OAuth Account Takeover

CVE-2026-48611, CVE-2026-48612

Weaknesses (CWE) in phpBB Authentication Bypass and OAuth Account Takeover

CWE-305, CWE-352

Timeline of phpBB Authentication Bypass and OAuth Account Takeover

  • Reporting traces the flawed authentication logic into the phpBB codebase circa 2014, where it remained for roughly a decade across the 3.x and 4.x branches.
  • Dan Stefan Alexandru of Pentest-Tools.com discovers the authentication bypass (PTT-2026-004) and the OAuth account-takeover flaw (PTT-2026-005).
  • Vulnerability reported to phpBB via its HackerOne Vulnerability Disclosure Program (per early Aikido/BleepingComputer reporting, submitted ~20:22 and triaged within minutes at ~20:31).
  • Flaws reported to the phpBB security team (per the Pentest-Tools.com technical advisory).
  • phpBB 3.3.17 ("Young Bertie") released as a maintenance and security update fixing four security issues including the critical auth bypass; OAuth redirect URI relocated under /user/oauth/authenticate/.
  • CVE identifiers CVE-2026-48611 (critical auth bypass, CVSS 9.4) and CVE-2026-48612 (OAuth account takeover, CVSS 8.3) assigned to the two flaws; no CISA KEV listing, EPSS score, or public PoC published at disclosure.
  • Public disclosure of PTT-2026-004 / PTT-2026-005, later assigned CVE-2026-48611 and CVE-2026-48612; root-cause technical details withheld to allow administrators to patch.
  • Widespread security-press coverage (Infosecurity Magazine, BleepingComputer, SC Media) amplifies the advisory, characterizing the bug as a single-request login-as-any-user flaw lurking for a decade and urging immediate upgrade to 3.3.17.

Sources cited for phpBB Authentication Bypass and OAuth Account Takeover

Detection coverage for TL-2026-0789

As of 2026-06-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0789 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats