Description
Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enumerate and delete other users' pending attachments.
Published: 2026-07-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A single‑character operator error in Simple Machines Forum’s AttachmentApprove.php causes the permission check to always succeed. An authenticated user with no approve_posts permission can approve, reject, or delete any pending attachment on any board. The flaw enables a low‑privileged attacker to bypass moderation queues for their own uploads, enumerate other users’ pending attachments, and delete them, thereby gaining unauthorized moderation capabilities.

Affected Systems

Simple Machines Forum versions 2.1 before commit 7d048f8 and 3.0 before commit a7875e8 are vulnerable. The CVE does not list explicit version numbers, so any installation of 2.1 or 3.0 that has not applied the referenced commits remains at risk. Check the source repository or the installed package version to verify whether the security fix has been incorporated.

Risk and Exploitability

The CVSS base score is 7.1, indicating a high severity. EPSS is < 1%, which suggests a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be an authenticated web session interacting with AttachmentApprove.php, as the flaw requires valid SMF credentials but does not grant full administrative rights. Given the absence of public exploits, the threat remains moderate to high for exposed installations lacking strict role separation.

Generated by OpenCVE AI on July 28, 2026 at 08:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a SMF release that includes the security fix in commit 7d048f8 for 2.1 or commit a7875e8 for 3.0.
  • Revoke the approve_posts permission from all users who are not intended moderators, ensuring that only authorized accounts retain that capability.
  • If upgrading cannot be performed immediately, block direct access to AttachmentApprove.php via server or .htaccess rules until the patch is applied.
  • Monitor attachment approval logs for abnormal activity and adjust permissions if suspicious patterns are detected.

Generated by OpenCVE AI on July 28, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Simplemachines simple Machines Forum
CPEs cpe:2.3:a:simplemachines:simple_machines_forum:*:*:*:*:*:*:*:*
cpe:2.3:a:simplemachines:simple_machines_forum:3.0.0:*:*:*:*:*:*:*
Vendors & Products Simplemachines simple Machines Forum

Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alpha 5 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enumerate and delete other users' pending attachments. Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enumerate and delete other users' pending attachments.

Tue, 14 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Simplemachines
Simplemachines smf
Vendors & Products Simplemachines
Simplemachines smf

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alpha 5 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enumerate and delete other users' pending attachments.
Title Simple Machines Forum Authorization Bypass via AttachmentApprove.php
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Simplemachines Simple Machines Forum Smf
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:48:45.607Z

Reserved: 2026-04-07T20:57:06.209Z

Link: CVE-2026-39903

cve-icon Vulnrichment

Updated: 2026-07-14T01:56:57.240Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses