PT-2026-57216 · Unknown · Simple Machines Forum

·

CVE-2026-39903

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Simple Machines Forum versions prior to 2.1.8 Simple Machines Forum versions prior to 3.0 Alpha 5
Description An authorization bypass exists in the Sources/Actions/AttachmentApprove.php file due to a single-character operator error that causes permission checks to always pass. This allows an authenticated low-privileged user to approve, reject, or delete any pending attachments on any board without the approve posts permission. Additionally, users can bypass moderation queues for their own uploads and enumerate or delete pending attachments belonging to other users.
Recommendations Update Simple Machines Forum 2.1 to version 2.1.8 or later. Update Simple Machines Forum 3.0 to version 3.0 Alpha 5 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39903

Affected Products

Simple Machines Forum