Threat reportVulnerabilityTL-2026-0789
phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17
phpBB Authentication Bypass and OAuth Account Takeover (TL-2026-0789), also tracked as PTT-2026-004, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-06-14. It has no confirmed attribution, affects phpBB phpBB (3.x branch), references 2 CVEs (CVE-2026-48611, CVE-2026-48612), maps to 17 MITRE ATT&CK techniques (T1078, T1087, T1098), and is covered by 9 detection rules and 19 indicators of compromise.
- CVSS
- 9.4/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-0789
- Threat ID
- TL-2026-0789
- Also known as
- PTT-2026-004, PTT-2026-005, phpBB decade-old auth bypass, phpBB silent account hijack
- Severity
- CRITICAL
- CVSS
- 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- online-communities, technology, media, gaming, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 19
How phpBB Authentication Bypass and OAuth Account Takeover works
A critical authentication bypass in phpBB (CVE-2026-48611, CVSS 9.4) let an unauthenticated attacker obtain a valid session as any active user — including administrators — with a single crafted HTTP request, requiring no password, prior access, or victim interaction, in the default database-authentication configuration. A companion OAuth account-takeover flaw (CVE-2026-48612, CVSS 8.3) silently links an attacker's credentials to a victim account via CSRF. Both were patched in phpBB 3.3.17 on June 6, 2026.
phpBB is one of the most widely deployed open-source PHP bulletin-board (forum) platforms, powering thousands of community forums and, per Pentest-Tools.com, tens of millions of users worldwide. In June 2026 two vulnerabilities were disclosed, tracked by the reporting researchers as PTT-2026-004 and PTT-2026-005 and later assigned CVE-2026-48611 and CVE-2026-48612.
PTT-2026-004 / CVE-2026-48611 is a critical authentication bypass (CVSS 9.4, CWE-305 Authentication Bypass by Primary Weakness) present in the phpBB codebase for roughly a decade (reporting traces the flawed logic to the 2014 era). A single unauthenticated HTTP request is sufficient to be handed a valid authenticated session as any chosen active account, including administrators. The attack requires no password, no special configuration, and no action by the victim, and is exploitable in the stock default configuration (auth_method=db). Because phpBB member lists are typically public, an attacker only needs a target username to take over the account. The vulnerability does NOT directly yield remote code execution: a separate password check guards the Admin Control Panel (ACP) and is not bypassed by this flaw. However, a hijacked administrator or moderator session still permits reading private messages and restricted forums, creating/modifying/deleting content and user accounts, impersonating staff, and defacing the board.
PTT-2026-005 / CVE-2026-48612 is a high-severity OAuth account-takeover weakness (CVSS 8.3, CWE-352 Cross-Site Request Forgery combined with missing OAuth state validation). It affects only boards where an administrator has enabled OAuth login with a supported provider (Google, Facebook, or Bitly) — a non-default configuration. By embedding a malicious link (for example inside an <img src="..."> tag in a forum post or private message) the attacker forces an authenticated victim's browser to silently bind the attacker's OAuth identity to the victim's account, granting the attacker persistent login access without any visible user interaction.
The flaws were discovered by Dan Stefan Alexandru of Pentest-Tools.com on May 13, 2026 and reported to the phpBB security team via its HackerOne Vulnerability Disclosure Program; phpBB triaged the report within minutes and shipped phpBB 3.3.17 ("Young Bertie"), a maintenance and security release fixing four security issues (one critical), on June 6, 2026, with public disclosure on June 8, 2026. The 3.x branch is fixed in 3.3.17; at disclosure time the 4.x branch (4.0.0-a2 and earlier) had no safe stable release and administrators were directed to the master branch. The 3.3.17 update relocates the OAuth redirect URI (to a path under /user/oauth/authenticate/...), which can break previously configured OAuth provider redirects until re-registered. As of disclosure no CISA KEV listing, no EPSS score, no public proof-of-concept, and no confirmed in-the-wild exploitation had been reported; the researchers withheld root-cause technical details to give administrators time to patch. NOTE: some early reporting (BleepingComputer / an Aikido write-up) credited the discovery to Aikido and cited a June 2 HackerOne timeline; the CVE-assigning technical advisory attributes discovery to Dan Stefan Alexandru of Pentest-Tools.com — both attributions are recorded in the timeline below.
MITRE ATT&CK techniques used in TL-2026-0789
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Discovery
Persistence
T1098 Account Manipulation; T1136 Create Account
Collection
T1185 Browser Session Hijacking; T1213 Data from Information Repositories
Credential Access
T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie; T1556 Modify Authentication Process
Impact
T1491 Defacement; T1565 Data Manipulation
Lateral Movement
lateral-movement
T1550 Use Alternate Authentication Material
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
Affected products and versions in phpBB Authentication Bypass and OAuth Account Takeover
- phpBB — phpBB (3.x branch)
Vulnerable versions: <= 3.3.16
Fixed in: 3.3.17 - phpBB — phpBB (4.x branch)
Vulnerable versions: <= 4.0.0-a2
Fixed in: master branch (no stable 4.x release at disclosure)
Remediation for phpBB Authentication Bypass and OAuth Account Takeover
Patches
- phpBB 3.3.17 ("Young Bertie"), released 2026-06-06 — fixes four security issues including the critical authentication bypass.
- phpBB 4.x: apply the patched master branch (no safe stable 4.x release at disclosure).
Immediate actions
- Upgrade phpBB 3.x boards to 3.3.17 or later immediately — this fixes both CVE-2026-48611 and CVE-2026-48612.
- For 4.x boards (4.0.0-a2 and earlier) with no safe stable release, update to the patched master branch per phpBB guidance.
- As an interim mitigation for the OAuth flaw, disable OAuth authentication and revert to database authentication.
- Audit the OAuth account-link records for unexpected or recently added provider bindings on privileged (admin/moderator) accounts and unlink any that are suspicious.
Workarounds
- Disable OAuth login and use database authentication only (mitigates CVE-2026-48612).
- Place the board behind a WAF rule alerting on anomalous authentication/session-grant responses while patching is scheduled.
Longer-term hardening
- After upgrading, re-register OAuth provider redirect URIs to the new /user/oauth/authenticate/... path, since 3.3.17 relocates the OAuth redirect URI and may break existing provider configs.
- Reset administrator and moderator credentials and invalidate active sessions on any board that was running a vulnerable version and reachable from the internet.
- Restrict or remove public member lists where feasible to raise the bar on target enumeration.
- Subscribe to phpBB security announcements and establish a routine patch cadence for the forum and its extensions.
CVEs associated with phpBB Authentication Bypass and OAuth Account Takeover
CVE-2026-48611, CVE-2026-48612
Weaknesses (CWE) in phpBB Authentication Bypass and OAuth Account Takeover
Timeline of phpBB Authentication Bypass and OAuth Account Takeover
- Reporting traces the flawed authentication logic into the phpBB codebase circa 2014, where it remained for roughly a decade across the 3.x and 4.x branches.
- Dan Stefan Alexandru of Pentest-Tools.com discovers the authentication bypass (PTT-2026-004) and the OAuth account-takeover flaw (PTT-2026-005).
- Vulnerability reported to phpBB via its HackerOne Vulnerability Disclosure Program (per early Aikido/BleepingComputer reporting, submitted ~20:22 and triaged within minutes at ~20:31).
- Flaws reported to the phpBB security team (per the Pentest-Tools.com technical advisory).
- phpBB 3.3.17 ("Young Bertie") released as a maintenance and security update fixing four security issues including the critical auth bypass; OAuth redirect URI relocated under /user/oauth/authenticate/.
- CVE identifiers CVE-2026-48611 (critical auth bypass, CVSS 9.4) and CVE-2026-48612 (OAuth account takeover, CVSS 8.3) assigned to the two flaws; no CISA KEV listing, EPSS score, or public PoC published at disclosure.
- Public disclosure of PTT-2026-004 / PTT-2026-005, later assigned CVE-2026-48611 and CVE-2026-48612; root-cause technical details withheld to allow administrators to patch.
- Widespread security-press coverage (Infosecurity Magazine, BleepingComputer, SC Media) amplifies the advisory, characterizing the bug as a single-request login-as-any-user flaw lurking for a decade and urging immediate upgrade to 3.3.17.
Sources cited for phpBB Authentication Bypass and OAuth Account Takeover
- phpBB authentication bypass: PTT-2026-004 and PTT-2026-005 (technical research)
- phpBB - Authentication bypass (CVE entry)
- Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request
- phpBB forum fixes auth bypass bug lurking for a decade
- Critical phpBB Vulnerability: Auth Bypass + RCE Since 2014 (Aikido)
- 10-year-old phpBB vulnerability allows admin account takeover
- phpBB rushes patch for silent account hijack
- phpBB 3.3.17 Release - Please update (official announcement)
Detection coverage for TL-2026-0789
As of 2026-06-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0789 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.