CVE-2026-47366
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.2 / 10
Vector String
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-284
Source
NVD
Vendor
phpBB
Product
phpBB
Discussion (0)
Add Comment
No comments yet. Be the first!