Authorization State-Confusion Vulnerability in Simple Machines Forum by Simple Machines
CVE-2026-43621

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-43621?

An authorization state-confusion vulnerability exists in Simple Machines Forum that permits authenticated low-privileged users to gain unauthorized administrator access. By manipulating multiple values of the user parameter during profile loading, attackers can exploit the discrepancy between profile ownership checks. This flaw allows them to impersonate an administrator, leading to unauthorized password changes and complete account compromise. Users are highly encouraged to update to versions beyond 2.1.7 to mitigate potential risks associated with this vulnerability.

Affected Version(s)

SMF 0 <= 2.1.7

SMF 0 <= 2.1.7

SMF 6f0dc61958aa86a4b436a222f6176812ed5bbb95

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

abdullah0x1337
.