Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.phpbb.com/community/viewtopic.php?t=2672170 |
|
History
Fri, 12 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Improper Permission Verification in phpBB ACP |
Fri, 12 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpbb
Phpbb phpbb |
|
| Vendors & Products |
Phpbb
Phpbb phpbb |
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface. | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-06-12T02:27:43.441Z
Reserved: 2026-05-19T15:00:09.320Z
Link: CVE-2026-47366
No data.
Status : Received
Published: 2026-06-12T04:17:05.390
Modified: 2026-06-12T04:17:05.390
Link: CVE-2026-47366
No data.
OpenCVE Enrichment
Updated: 2026-06-12T05:00:17Z
Weaknesses