:

PHPBB PATCHES 10-YEAR AUTH BYPASS FLAW

INDUSTRY DESK1 MIN READ
FRI, JUN 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

phpBB has fixed a critical authentication bypass vulnerability that existed for a decade, allowing attackers to log in as any user including administrators. The flaw was discovered and patched in the latest release.

The vulnerability in phpBB forum software enabled attackers to bypass authentication mechanisms and gain unauthorized access to user accounts at any privilege level. An attacker exploiting the flaw could compromise administrator accounts, leading to full control over forum operations, user data, and system settings. The bug remained undetected for ten years before discovery, raising concerns about how many instances may have been compromised during that period. phpBB maintainers released a patch addressing the issue, and users are advised to update immediately. The exact technical details of the vulnerability remain limited as the patch rolls out. phpBB recommends all administrators apply updates to vulnerable installations and consider reviewing access logs for suspicious activity. Forum owners should also reset passwords for critical accounts as a precaution. This incident underscores the security risks in legacy software and the importance of regular updates, even for established open-source projects.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

An unnamed British police officer faces criminal investigation for allegedly using artificial intelligence to create evidence in multiple cases. The officer has been removed from frontline duties in what authorities describe as the first known case of its kind in the UK.

6H AGOAI Desk

A growing market of DIY gadgets in China allows drivers to circumvent Tesla's distracted-driving safeguards. Tiny plastic heads, blinking screens, and celebrity figurines trick the vehicle's camera into thinking the driver is paying attention.

6H AGOIndustry Desk

Section 702 of the Foreign Intelligence Surveillance Act expires tonight, but surveillance operations will proceed under a certification that remains valid until March 2027.

6H AGOIndustry Desk

Security researchers discovered that malware developers embedded references to nuclear and biological weapons in their spyware code, raising questions about the intent and sophistication of the attack.

6H AGODev Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.