# phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17

> A critical authentication bypass in phpBB (CVE-2026-48611, CVSS 9.4) let an unauthenticated attacker obtain a valid session as any active user — including administrators — with a single crafted HTTP request, requiring no password, prior access, or victim interaction, in the default database-authentication configuration. A companion OAuth account-takeover flaw (CVE-2026-48612, CVSS 8.3) silently links an attacker's credentials to a victim account via CSRF. Both were patched in phpBB 3.3.17 on June 6, 2026.

- **Published:** 2026-06-14T00:00:00Z
- **Last reviewed:** 2026-06-14T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0789
- **ID:** TL-2026-0789
- **Severity:** CRITICAL (CVSS 9.4)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-48611, CVE-2026-48612

## Description

phpBB is one of the most widely deployed open-source PHP bulletin-board (forum) platforms, powering thousands of community forums and, per Pentest-Tools.com, tens of millions of users worldwide. In June 2026 two vulnerabilities were disclosed, tracked by the reporting researchers as PTT-2026-004 and PTT-2026-005 and later assigned CVE-2026-48611 and CVE-2026-48612.

PTT-2026-004 / CVE-2026-48611 is a critical authentication bypass (CVSS 9.4, CWE-305 Authentication Bypass by Primary Weakness) present in the phpBB codebase for roughly a decade (reporting traces the flawed logic to the 2014 era). A single unauthenticated HTTP request is sufficient to be handed a valid authenticated session as any chosen active account, including administrators. The attack requires no password, no special configuration, and no action by the victim, and is exploitable in the stock default configuration (auth_method=db). Because phpBB member lists are typically public, an attacker only needs a target username to take over the account. The vulnerability does NOT directly yield remote code execution: a separate password check guards the Admin Control Panel (ACP) and is not bypassed by this flaw. However, a hijacked administrator or moderator session still permits reading private messages and restricted forums, creating/modifying/deleting content and user accounts, impersonating staff, and defacing the board.

PTT-2026-005 / CVE-2026-48612 is a high-severity OAuth account-takeover weakness (CVSS 8.3, CWE-352 Cross-Site Request Forgery combined with missing OAuth state validation). It affects only boards where an administrator has enabled OAuth login with a supported provider (Google, Facebook, or Bitly) — a non-default configuration. By embedding a malicious link (for example inside an <img src="..."> tag in a forum post or private message) the attacker forces an authenticated victim's browser to silently bind the attacker's OAuth identity to the victim's account, granting the attacker persistent login access without any visible user interaction.

The flaws were discovered by Dan Stefan Alexandru of Pentest-Tools.com on May 13, 2026 and reported to the phpBB security team via its HackerOne Vulnerability Disclosure Program; phpBB triaged the report within minutes and shipped phpBB 3.3.17 ("Young Bertie"), a maintenance and security release fixing four security issues (one critical), on June 6, 2026, with public disclosure on June 8, 2026. The 3.x branch is fixed in 3.3.17; at disclosure time the 4.x branch (4.0.0-a2 and earlier) had no safe stable release and administrators were directed to the master branch. The 3.3.17 update relocates the OAuth redirect URI (to a path under /user/oauth/authenticate/...), which can break previously configured OAuth provider redirects until re-registered. As of disclosure no CISA KEV listing, no EPSS score, no public proof-of-concept, and no confirmed in-the-wild exploitation had been reported; the researchers withheld root-cause technical details to give administrators time to patch. NOTE: some early reporting (BleepingComputer / an Aikido write-up) credited the discovery to Aikido and cited a June 2 HackerOne timeline; the CVE-assigning technical advisory attributes discovery to Dan Stefan Alexandru of Pentest-Tools.com — both attributions are recorded in the timeline below.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1593 Search Open Websites/Domains
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1078 Valid Accounts
- T1556 Modify Authentication Process
- T1539 Steal Web Session Cookie
- T1212 Exploitation for Credential Access
- T1534 Internal Spearphishing
- T1550 Use Alternate Authentication Material
- T1098 Account Manipulation
- T1136 Create Account
- T1185 Browser Session Hijacking
- T1087 Account Discovery
- T1213 Data from Information Repositories
- T1565 Data Manipulation
- T1491 Defacement

## Sources

- [phpBB authentication bypass: PTT-2026-004 and PTT-2026-005 (technical research)](https://pentest-tools.com/research/phpbb-authentication-bypass)
- [phpBB - Authentication bypass (CVE entry)](https://pentest-tools.com/vulnerabilities-exploits/phpbb-authentication-bypass_29369)
- [Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request](https://www.infosecurity-magazine.com/news/phpbb-authentication-bypass/)
- [phpBB forum fixes auth bypass bug lurking for a decade](https://www.bleepingcomputer.com/news/security/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade/)
- [Critical phpBB Vulnerability: Auth Bypass + RCE Since 2014 (Aikido)](https://www.aikido.dev/blog/phpbb-authentication-bypass-rce)
- [10-year-old phpBB vulnerability allows admin account takeover](https://www.scworld.com/brief/10-year-old-phpbb-vulnerability-allows-admin-account-takeover)
- [phpBB rushes patch for silent account hijack](https://thearabianpost.com/phpbb-rushes-patch-for-silent-account-hijack/)
- [phpBB 3.3.17 Release - Please update (official announcement)](https://www.phpbb.com/community/viewtopic.php?t=2672170)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0789
