:

PHPBB PATCHES 10-YEAR AUTH BYPASS FLAW

INDUSTRY DESK1 MIN READ
FRI, JUN 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

phpBB has fixed a critical authentication bypass vulnerability that existed for a decade, allowing attackers to log in as any user including administrators. The flaw was discovered and patched in the latest release.

The vulnerability in phpBB forum software enabled attackers to bypass authentication mechanisms and gain unauthorized access to user accounts at any privilege level. An attacker exploiting the flaw could compromise administrator accounts, leading to full control over forum operations, user data, and system settings. The bug remained undetected for ten years before discovery, raising concerns about how many instances may have been compromised during that period. phpBB maintainers released a patch addressing the issue, and users are advised to update immediately. The exact technical details of the vulnerability remain limited as the patch rolls out. phpBB recommends all administrators apply updates to vulnerable installations and consider reviewing access logs for suspicious activity. Forum owners should also reset passwords for critical accounts as a precaution. This incident underscores the security risks in legacy software and the importance of regular updates, even for established open-source projects.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.

1H AGOIndustry Desk

Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.

1H AGOIndustry Desk

GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.

2H AGOIndustry Desk

A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.

2H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.