Description
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
References (1)
Core 1
Core References
Scores
CVSS v3
7.2
EPSS
0.0026
EPSS Percentile
17.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (1)
phpBB/phpBB
3.3.0 - 3.3.16
Published
Jun 12, 2026
Tracked Since
Jun 12, 2026