URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Got a car for sale? Here's the place for it.
PLEASE be sure to add your V.I.N or rego details and location details.

Moderators: reidy, Blacky

Forum rules
All items here will be automatically deleted after 6 months since the last post. This will give you ample time to sell your item.
Post Reply
User avatar
admin
Posts: 22
Joined: Mon Feb 02, 2004 3:25 pm
State: VIC
Location: Melbourne

URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by admin »

You need to update your board to phpBB 3.3.17 immediately. ALL versions from 3.1.0 to 3.3.16 (which covers over 10 years of phpBB releases) contain a critical vulnerability CVE-2026-48611.

The Reality of the Vulnerability
The official phpBB developers handled this disclosure extremely poorly. In their 3.3.17 release announcement, they buried this catastrophic flaw in the middle of normal text as if it were a minor bug: "Furthermore, two separate improper checks in the previous OAuth implementation could have been used to hijack user accounts."

Do not let that wording fool you. In reality, this vulnerability allows ANY UNAUTHENTICATED ATTACKER to log in as ANY USER on the forum, without any extra checks.

There is no complex setup required. The exploit is literally a single URL query. An attacker can use a 1-line curl command and instantly receive valid cookies to authenticate as any user they choose.

All an attacker needs to know is a target's username, which is trivially easy to find on 99% of forums. They will target moderator and admin accounts. Here is what that actually means for your board:
  • Attackers get full access to everything the hijacked user has, including reading all Private Messages (DMs).
  • By logging in as an admin or moderator, they gain full access to the Moderator Control Panel (MCP).
  • From the MCP, the attacker can check all moderation logs, delete threads, ban users, and expose the private email addresses of every user on your forum.
Exploits Are Trivial to Create
Security researchers at Aikido are holding back technical details, but that does not keep you safe. Because the exploit is so simple, anyone with an LLM can trivially analyze the 3.3.17 patchset, identify the exact flaw in 5-10 minutes, and have a working Proof of Concept (PoC) ready to go.

Aikido privately notified a handful of the largest online communities, but THOUSANDS of popular phpBB forums are still vulnerable right now because they haven't gotten the news.

Do not wait for someone to target your board. UPDATE TO 3.3.17 NOW.
User avatar
Brett027
Posts: 2517
Joined: Thu Apr 18, 2019 4:14 am
State: NSW

Re: URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by Brett027 »

What does this mean? If it is a true message from admin and we need to do something then show us how to do it please. I for one have no idea whether this is nonsense or serious.
Sucker for a rusty bomb
User avatar
Errol62
Posts: 11591
Joined: Sat Dec 06, 2014 2:44 pm
State: SA
Location: Adelaide

Re: URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by Errol62 »

Appears legit to me although I don’t know what is meant by updating your board.


Sent from my iPhone using Tapatalk
getting my FB ute on the road
EK van on rotisserie
Blacky
Posts: 14175
Joined: Tue Jul 20, 2004 8:58 am
State: WA
Location: up in the Perth hills

Re: URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by Blacky »

Let me check with Jason - seems to be a very impersonal message
I started with nothing and still have most of it left.


Foundation member #61 of FB/EK Holden club of W.A.
User avatar
Craig Allardyce
Posts: 1561
Joined: Sun Aug 07, 2011 7:26 pm
State: VIC
Location: Stratford

Re: URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by Craig Allardyce »

We haven't seen this on our Classic Australian Wooden Powerboat Association forum which uses the same phpBB platform. Jason also manages that for us. Maybe a bit suss.
Blacky
Posts: 14175
Joined: Tue Jul 20, 2004 8:58 am
State: WA
Location: up in the Perth hills

Re: URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by Blacky »

This post is NOT from Jason - he has confirmed that tonight. There are others in the VIC club that have access to the forum admin persona though , we are in the process of chasing them down and see if they posted it but it appears it’s a scam at this point.
I started with nothing and still have most of it left.


Foundation member #61 of FB/EK Holden club of W.A.
Post Reply