Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.phpbb.com/community/viewtopic.php?t=2672170 |
|
History
Fri, 12 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Improper Permission Verification in phpBB ACP |
Fri, 12 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpbb
Phpbb phpbb |
|
| Vendors & Products |
Phpbb
Phpbb phpbb |
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface. | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-06-12T02:27:43.441Z
Updated: 2026-06-12T12:26:51.773Z
Reserved: 2026-05-19T15:00:09.320Z
Link: CVE-2026-47366
Updated: 2026-06-12T12:26:47.849Z
Status : Deferred
Published: 2026-06-12T04:17:05.390
Modified: 2026-06-12T16:07:34.850
Link: CVE-2026-47366
No data.