Executive brief
Simple Machines Forum, a popular open-source community software, contains a flaw that allows regular users to perform administrative actions on file attachments. An attacker with a standard account can approve, reject, or delete files uploaded by other users across the entire forum. This could lead to the unauthorized removal of community content or the bypassing of security moderation queues intended to prevent malicious files from being posted.
Technical details
An authorization bypass vulnerability exists in Simple Machines Forum (SMF) versions 2.1.x before 2.1.8 and 3.0.x before 3.0 Alpha 5. The flaw is located in the attachment approval logic (specifically Sources/Actions/AttachmentApprove.php and Sources/ManageAttachments.php) where a single-character typo—using an assignment operator (=) instead of a comparison operator (==)—causes permission checks to evaluate as true. An authenticated attacker with low privileges can exploit this over the network to approve, reject, or delete pending attachments on any board, effectively bypassing the 'approve_posts' permission requirement. This also allows users to bypass moderation queues for their own uploads and enumerate or delete other users' pending files. The issue has been patched in versions 2.1.8 and 3.0 Alpha 5.
Affected products
- SimpleMachines SMF (Simple Machines Forum) 2.1.0 to 2.1.7, 3.0.0 to 3.0.0 Alpha 4
Timeline
- 2026-04-08: patched: Fixes merged into 2.1 and 3.0 branches
- 2026-07-10: disclosed: CVE published and NVD record created
References
- https://github.com/SimpleMachines/SMF/commit/7d048f8d66aab9af51cd6ee110fbad103cf673e8
- https://github.com/SimpleMachines/SMF/commit/a7875e876a647572dd4c45da881b875092caac3d
- https://github.com/SimpleMachines/SMF/pull/9181
- https://github.com/SimpleMachines/SMF/pull/9182
- https://www.vulncheck.com/advisories/simple-machines-forum-authorization-bypass-via-attachmentapprove-php