๐Ÿ” CVE Alert

CVE-2026-43621

UNKNOWN 0.0

Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.

CWE CWE-863
Vendor simplemachines
Product smf
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for simplemachines smf

Be the first to know when new unknown vulnerabilities affecting simplemachines smf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

SimpleMachines / SMF
0 โ‰ค 2.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SimpleMachines/SMF/commit/6f0dc61958aa86a4b436a222f6176812ed5bbb95 vulncheck.com: https://www.vulncheck.com/advisories/simple-machines-forum-authorization-confusion-via-profile-load

Credits

abdullah0x1337