CVE 7.2 HIGH

CVE-2026-47366_CVE-2026-47366

7.2 / 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.

Basic Information

ID CVE-2026-47366
Source hackerone
Published Jun 12, 2026 at 02:27

Affected Product

Vendor phpBB
Product phpBB
Version 3.3.0
Affected Versions phpBB phpBB 3.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.