<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c" -->

---
title: phpBB forum fixes auth bypass bug lurking for a decade
description: A 10-year-old authentication bypass vulnerability in phpBB forum software allows attackers to log in as any user, including administrators, with a single HTTP...
canonical: https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: phpBB forum fixes auth bypass bug lurking for a decade | daily.dev
og:description: A 10-year-old authentication bypass vulnerability in phpBB forum software allows attackers to log in as any user, including administrators, with a single HTTP...
og:url: https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c
og:image: https://api.daily.dev/og/posts/khey5ws8C.png
og:image:alt: phpBB forum fixes auth bypass bug lurking for a decade
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# phpBB forum fixes auth bypass bug lurking for a decade

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 1 comments

## Summary

A 10-year-old authentication bypass vulnerability in phpBB forum software allows attackers to log in as any user, including administrators, with a single HTTP request and no special configuration. The flaw affects all phpBB 3.x versions up to 3.3.16 and 4.x up to 4.0.0-a2. Discovered by Aikido Security on June 2nd and reported via HackerOne, phpBB patched the issue in version 3.3.17 on June 6th. No fix is yet available for the 4.x branch. While RCE is not possible due to a separate Admin Control Panel password check, successful exploitation could expose private messages, allow content manipulation, account impersonation, and site defacement. Aikido is withholding full technical details to give administrators time to patch.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade>

## Community discussion

Top comments from developers on daily.dev.

**@astrootter** · 0 upvotes

> Wow this dude is still alive :o

## Similar posts on daily.dev

- [Critical phpBB Vulnerability: Auth Bypass \+ RCE Since 2014](https://daily.dev/posts/critical-phpbb-vulnerability-auth-bypass-rce-since-2014-636hneaei) · Aikido Security · 0 upvotes · 0 comments
- [Authentication Bypass in the default configuration phpBB](https://daily.dev/posts/authentication-bypass-in-the-default-configuration-phpbb-3luvbkktq) · Aikido Security · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#php](https://daily.dev/tags/php)

[View this post on daily.dev](https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"phpBB forum fixes auth bypass bug lurking for a decade","url":"https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c"},"datePublished":"2026-06-12T18:21:10.365Z","dateModified":"2026-06-12T18:23:48.962Z","description":"A 10-year-old authentication bypass vulnerability in phpBB forum software allows attackers to log in as any user, including administrators, with a single HTTP...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9cddeb824023a53abe5508ca0d81e80d?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9cddeb824023a53abe5508ca0d81e80d?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,open-source,php","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"phpBB forum fixes auth bypass bug lurking for a decade"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade-khey5ws8c","comment":[{"@type":"Comment","text":"Wow this dude is still alive :o","datePublished":"2026-06-17T13:02:19.075Z","url":"https://daily.dev/posts/khey5ws8C#c-n9e5m2Of9","author":{"@type":"Person","name":"Stephane","url":"https://daily.dev/astrootter","image":"https://avatars.githubusercontent.com/u/7487421?v=4"}}]}
```

