phpBB fixes decade-old authentication bypass that can let attackers log in as any forum user

phpBB has fixed a long-hidden security flaw that can let an attacker sign in as any user on affected forums, including administrators. The bug has no CVE yet and affects phpBB 3.3.16 and earlier plus 4.0.0-a2; phpBB says version 3.3.17 fixes the 3.x branch, while no safe 4.x release is available yet. Researchers said the issue is trivial to exploit with a single HTTP request in default configurations, though separate checks reportedly prevent direct remote code execution through the admin panel.
Why it matters: Forum operators should treat this as urgent because an attacker could impersonate staff, read private messages, and alter or delete content without needing special setup. Update phpBB 3.x to 3.3.17 immediately, and admins on 4.0.0-a2 should move to the patched master branch or apply vendor guidance as soon as possible.

Sources

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
SecurityWeek News 2026.06.19 93% relevant
This article recaps the same phpBB flaw and adds actionable version detail: affected versions up to 3.3.16 and 4.0.0-a2, patched in 3.3.17, with unauthenticated impersonation possible via a single HTTP request.
phpBB forum fixes auth bypass bug lurking for a decade
Bill Toulas 2026.06.12 100% relevant
This article establishes a new tracked story because it reports the discovery and vendor fix of a distinct phpBB authentication bypass affecting broad deployed versions, and it does not match any existing tracked event.
← Back to all stories