After more 2 000 000 (two million) views on forum for 1.5.0.x development versions... and 1.6.1.0, 1.6.3.0-dev versions
A new stable version, UltraVNC 1.6.4.0 and UltraVNC SC 1.6.4.0 have been released: https://forum.uvnc.com/viewtopic.php?t=38095
Feedback is always welcome

2026-04-01: After 1.7.x, 1.8.x release builds need tests and feedback: https://forum.uvnc.com/viewtopic.php?t=38158

2026-03-11: CVE-2026-3787 and CVE-2026-4962 - Clarification: https://forum.uvnc.com/viewtopic.php?t=38155

2025-12-02: We need help: English Wikipedia UltraVNC page has been requested to deletion: https://forum.uvnc.com/viewtopic.php?t=38127
Any help is welcome to improve the UltraVNC page and/or to comment on the Wikipedia Talk page

2025-05-06: Forum password change request: https://forum.uvnc.com/viewtopic.php?t=38078

2023-09-21: Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864

Development: UltraVNC development is always here... Any help is welcome
Feedback is welcome

Help is very needed for:
Windows ARM/ARM64 support: https://forum.uvnc.com/viewtopic.php?t=38163 / https://github.com/ultravnc/UltraVNC/issues/346
macOS support: https://forum.uvnc.com/viewtopic.php?t=38164 / https://github.com/ultravnc/UltraVNC/issues/347
Linux support: https://forum.uvnc.com/viewtopic.php?t=38165 / https://github.com/ultravnc/UltraVNC/issues/348
*BSD support: https://forum.uvnc.com/viewtopic.php?t=38166 / https://github.com/ultravnc/UltraVNC/issues/349
*Solaris support: https://forum.uvnc.com/viewtopic.php?t=38167 / https://github.com/ultravnc/UltraVNC/issues/350

URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Here you will find help for frequently asked questions as well as for your specific question
Post Reply
Ludovic
Admin & Developer
Admin & Developer
Posts: 195
Joined: 2021-12-28 18:55

URGENT WARNING: Critical phpBB Authentication Bypass - UPDATE TO 3.3.17 IMMEDIATELY

Post by Ludovic »

You need to update your board to phpBB 3.3.17 immediately. ALL versions from 3.1.0 to 3.3.16 (which covers over 10 years of phpBB releases) contain a critical vulnerability CVE-2026-48611.

The Reality of the Vulnerability
The official phpBB developers handled this disclosure extremely poorly. In their 3.3.17 release announcement, they buried this catastrophic flaw in the middle of normal text as if it were a minor bug: "Furthermore, two separate improper checks in the previous OAuth implementation could have been used to hijack user accounts."

Do not let that wording fool you. In reality, this vulnerability allows ANY UNAUTHENTICATED ATTACKER to log in as ANY USER on the forum, without any extra checks.

There is no complex setup required. The exploit is literally a single URL query. An attacker can use a 1-line curl command and instantly receive valid cookies to authenticate as any user they choose.

All an attacker needs to know is a target's username, which is trivially easy to find on 99% of forums. They will target moderator and admin accounts. Here is what that actually means for your board:
  • Attackers get full access to everything the hijacked user has, including reading all Private Messages (DMs).
  • By logging in as an admin or moderator, they gain full access to the Moderator Control Panel (MCP).
  • From the MCP, the attacker can check all moderation logs, delete threads, ban users, and expose the private email addresses of every user on your forum.
Exploits Are Trivial to Create
Security researchers at Aikido are holding back technical details, but that does not keep you safe. Because the exploit is so simple, anyone with an LLM can trivially analyze the 3.3.17 patchset, identify the exact flaw in 5-10 minutes, and have a working Proof of Concept (PoC) ready to go.

Aikido privately notified a handful of the largest online communities, but THOUSANDS of popular phpBB forums are still vulnerable right now because they haven't gotten the news.

Do not wait for someone to target your board. UPDATE TO 3.3.17 NOW.
UltraVNC links (join us on social networks):
- Website: https://uvnc.com/
- Forum: https://forum.uvnc.com/
- GitHub sourcecode: https://github.com/ultravnc/UltraVNC
- Mastodon: https://mastodon.social/@ultravnc
- Bluesky/AT Protocol: https://bsky.app/profile/ultravnc.bsky.social
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
- uvnc2me: https://uvnc2me.com/
Post Reply