Home

Description

Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.

PUBLISHED Reserved 2026-05-19 | Published 2026-06-12 | Updated 2026-06-12 | Assigner hackerone




HIGH: 7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-284 Improper Access Control - Generic

Product status

Default status
unaffected

3.3.0 (semver)
affected

References

www.phpbb.com/community/viewtopic.php?t=2672170

cve.org (CVE-2026-47366)

nvd.nist.gov (CVE-2026-47366)

Download JSON