Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-43621— Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()

Quick assessment

Affected
SimpleMachines SMF
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Simple Machines Forum(SMF)在 2.1.7 及之前版本中存在一个授权状态混淆漏洞,该漏洞已在提交 6f0dc61 中修复。此漏洞位于用户个人资料(profile)加载器中,允许已认证的普通低权限用户通过为 参数传递多个值,从而获取管理员权限。攻击者可利用连续加载个人资料时 与 之间的状态不一致,使系统将其视为某个管理员个人资料的拥有者,进而实施未授权的密码修改,最终实现完全账户接管。

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-43621

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()
Source: CVE Program / CVE List V5
Vulnerability Description
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SimpleMachines SMF 0 ~ 2.1.7 -

II. Public POCs for CVE-2026-43621

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-43621

登录查看更多情报信息。

Patches & Fixes for CVE-2026-43621 (1)

Vendor Advisories for CVE-2026-43621 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-43621

No comments yet


Leave a comment