惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
博客园 - 【当耐特】
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
雷峰网
雷峰网
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
B
Blog RSS Feed
H
Help Net Security
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
L
LangChain Blog
Vercel News
Vercel News

Aikido Security's Blog

GlassWorm goes native: New Zig dropper infects every IDE on your machine Aikido Attack finds multiple 0-days in Hoppscotch The cybersecurity doomerism around Mythos doesn't match what we see on the ground axios compromised on npm: maintainer account hijacked, RAT deployed Popular telnyx package compromised on PyPI by TeamPCP Aikido × Lovable: Vibe, Fix, Ship CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran TeamPCP deploys CanisterWorm on NPM following Trivy compromise Security testing is validating software that no longer exists Aikido Recognized by Frost & Sullivan with the 2026 Customer Value Leadership Award in ASPM GlassWorm Hides a RAT Inside a Malicious Chrome Extension fast-draft Open VSX Extension Compromised by BlokTrooper Glassworm Strikes Popular React Native Phone Number Packages Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories How Security Teams Fight Back Against AI-Powered Hackers Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks Trump’s 2026 cybersecurity strategy: From compliance to consequence How does AI pentesting work with compliance? What continuous pentesting actually requires Rare Not Random: Using Token Efficiency for Secrets Scanning Persistent XSS/RCE using WebSockets in Storybook’s dev server Why Determinism Is Still a Necessity in Security WAF vs. RASP vs. ADR Introducing Aikido Infinite: A new model of self-securing software How Aikido secures AI pentesting agents by design Astro Full-Read SSRF via Host Header Injection How to Get Your Board to Care About Security (Before a Breach Forces the Issue) What is Slopsquatting? The AI Package Hallucination Attack Already Happening SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel Top 6 Wiz Code Alternatives
10 year old critical vulnerability in phpBB affecting ten...
Jorian Woltjer · 2026-06-10 · via Aikido Security's Blog

Published on:

Jun 10, 2026

Aikido's AI pentesting tool Aikido Attack discovered a critical Authentication Bypass vulnerability in the latest version of the forum software phpBB. The vulnerability is exploitable in the default configuration and requires no special knowledge. If you are on version 4.0.0-a2 or 3.3.16 and below, upgrade immediately to master (no safe 4.x release yet) and 3.3.17, respectively, to avoid compromise. 

On June 2nd, we reported the find to the phpBB maintainers through their HackerOne Vulnerability Disclosure Program. After a quick triage, it took only 4 days for a working patch to be released in the new version 3.3.17 on June 6th. You can read more details about this update on the official release notes.

There is a small breaking change if your phpBB instance has OAuth authentication enabled, as the redirect URI handler is now located at /user/oauth/authenticate/.... Apart from this change, the upgrade should be a smooth process.

To give administrators time to upgrade, we are holding back on publishing technical details for now, but we will follow up with a second article in the near future.

We've already privately notified administrators of the largest online communities of the update, but ask you to help reach out to any instances you know that might not have gotten the news yet.

About phpBB

phpBB is an old piece of open-source forum software from the year 2000 that’s still being used today. You might recognize some of the communities that phpBB powers, like https://forum.joomla.org or https://forums.debian.net. phpBB's Site Showcase alone has over 6 million members, with many more in unlinked instances.

Due to its popularity and open-source nature, it faced many targeted attacks exploiting 0-days across the internet back in the day. The most notable is the "Santy" worm in 2004, which abused a vulnerability resulting in RCE. It was the first time a search engine like Google was used to instantly find and compromise tens of thousands of instances.

The attack surface is vast, with many features slowly making their way into the codebase over the years. And raw PHP isn't exactly considered the safest framework. Nonetheless, they have a proper Vulnerability Disclosure Program on HackerOne where researchers can get their findings fixed.

Nowadays, it is considered reasonably secure. But we have new evidence that it still contains highly impactful vulnerabilities.

A single unauthenticated HTTP request is enough to obtain a valid session as any user. On a default phpBB install the member list is public, so picking a target is trivial.

Posted January 2014. Still no replies.

What an attacker can do with that session depends on the account. A standard user exposes private messages and all content they can access. An administrator account gives full read, write and delete access across the forum. Anyone can be impersonated, and any private conversation can be leaked.

Remote Code Execution is not directly possible with this vulnerability, even on the latest version with the Extension Catalog, because there is another password check in front of the Admin Control Panel (ACP) that cannot be bypassed. This limits the impact to admin account takeover.

The vulnerability affects all versions up to and including 3.3.16 and 4.0.0-a2.

Timeline

  • June 2, 2026 20:22 PM - Submitted report to https://hackerone.com/phpbb VDP program
  • June 2, 2026 20:31 PM - Report was triaged by phpBB staff (that's right, 9 minutes!)
  • June 6, 2026 16:26 PM - Version 3.3.17 with a patch is released

Last updated on:

Jun 11, 2026

Tired of false positives?

Try Aikido like 100k others.

Start Now

Get a personalized walkthrough

Trusted by 100k+ teams

Book Now

Scan your app for IDORs and real attack paths

Trusted by 100k+ teams

Start Scanning

See how AI pentests your app

Trusted by 100k+ teams

Start Testing

Vulnerabilities & Threats

Compromised Rust crate onering performs code exfiltration

The compromised onering Rust crate v1.4.1 on crates.io shipped a malicious build.rs that exfiltrates the diff of your latest commit to a hosted Sentry endpoint every time you build.

Vulnerabilities & Threats

Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System

Deep dive into binding.gyp, the often overlooked npm build file that can execute malicious code at install time through shell expansions, sandbox escapes, and compiler hijacking.

Vulnerabilities & Threats

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines.

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.