PT-2026-57163 · Pypi · Flaskbb

·

CVE-2026-22660

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FlaskBB versions prior to 2.2.1
Description A logic flaw exists that allows authenticated administrators to delete all built-in authorization groups. This occurs due to a type mismatch in the bulk delete protection check within the management views bulk AJAX endpoint. The system compares received JSON integer group IDs against string literals, which causes the protection check to always pass. This action destroys the forum's permission model and can render the site unusable.
Recommendations Update FlaskBB to version 2.2.1 or later to apply the fix implemented in commit a5da9a5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22660
GHSA-R9CF-JXR6-5H3R

Affected Products

Flaskbb