Greetings everyone,
As mentioned in the release announcement of phpBB 3.3.17, a security issue noticed in phpBB versions 3.3.16 and prior could have been used to hijack user accounts. Due to the criticality of this issue, we urge admins to update to 3.3.17 as soon as possible or disable access to their forums until they manage to do so.
If you are not able to update to 3.3.17 yet and do not use Apache or LDAP authentication on your board, you can remove the following two files as a temporary workaround ({root} used as indicator of the forum root directory):
{root}/phpbb/auth/provider/apache.php
{root}/phpbb/auth/provider/ldap.php
In addition to that, we recommend that you disable OAuth in the ACP until you find ample time to update.
Note: This workaround will result in an error when visiting the authentication provider page in the ACP. You can add the files back when updating to 3.3.17 and the error should then be resolved.
- The phpBB Team
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | PHP Type Juggling: как нестрогое сравнение превращается в обход аутентификации | 0 | 8.1 | 22-07-2026 |
| 2 | Предложение на Форум | 2 | 3 | 27-06-2026 |
| 3 | The Fragile Lock: Novel Bypasses For SAML Authentication | 0 | 8 | 10-12-2025 |
| 4 | Looper not showing author? | 0 | 3 | 12-07-2026 |
| 5 | Announcing FusionAuth 1.63 - The Proof Pangolin | 0 | 12.67 | 26-02-2026 |
| 6 | milpa/auth (v0.3.0) | 0 | 10.94 | 28-07-2026 |
| 7 | BuddyPress 14.5.0, 12.7.0 & 11.6.0 Maintenance and Security Releases | 0 | 30.58 | 08-07-2026 |
| 8 | Mike Witt replied to the topic Unauthenticated Arbitrary Shortcode Execution Security Vulnerability in the forum Requests & Feedback | 0 | 5 | 30-01-2026 |
| 9 | litestar-auth - auth backend для litestar | 0 | 26.67 | 10-05-2026 |