
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48611 is a critical improper authentication vulnerability in phpBB's OAuth implementation that allows unauthenticated remote attackers to hijack user accounts, even when OAuth is not configured or enabled, affecting default installations. The vulnerability affects phpBB versions 3.3.0 through 3.3.16 and was published on June 12, 2026, with a patch made available the same day via GitHub Advisory GHSA-24pr-8ggp-h88c. It carries a CVSS v3.0 base score of 9.8 (Critical) (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-287 (Improper Authentication): phpBB's OAuth implementation fails to properly validate authentication claims, allowing an attacker to bypass the authentication mechanism entirely — even on installations where OAuth has never been configured or enabled. This means the vulnerable code path is reachable in default phpBB deployments without any special configuration. The attack vector is network-based, requires no privileges, no user interaction, and has low attack complexity, making it trivially exploitable by unauthenticated remote attackers. A phpBB community forum thread and a Pentest Tools research write-up provide additional technical context (GitHub Advisory, Pentest Tools, phpBB Forum).
Successful exploitation allows an unauthenticated attacker to hijack arbitrary user accounts, gaining full unauthorized access to the affected phpBB installation. This results in high confidentiality impact (access to private messages, user data, and forum content), high integrity impact (ability to modify posts, account settings, and potentially escalate to administrator), and high availability impact. Given that phpBB is widely deployed in community and educational contexts, compromise could expose sensitive user data and enable further lateral movement within the hosting environment (GitHub Advisory, The Hacker Wire).
A proof-of-concept repository (CVE-2026-48611-poc) written in JavaScript was published on GitHub shortly after disclosure, though its classification as a functional exploit remains unconfirmed based on available metadata (Feedly). A second exploit repository (CVE-2026-48611-EXPLOIT) also appeared on GitHub approximately five days after initial disclosure (Vulners). The EPSS score is approximately 0.075%–0.416%, indicating a relatively low but non-negligible probability of exploitation in the near term. There is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of reporting (GitHub Advisory, ENISA EUVD).
phpBB version strings) or internet scanning tools like Shodan/Censys./ucp.php?mode=login&login=external) from unexpected or anonymous IP addresses; repeated authentication attempts without corresponding valid credential submissions.Apply the available patch immediately by upgrading phpBB to a version beyond 3.3.16, as referenced in GitHub Advisory GHSA-24pr-8ggp-h88c. If immediate patching is not possible, consider disabling OAuth-related functionality at the application or web server level, and implement network-level access controls (e.g., IP allowlisting) to restrict forum access. Administrators should also audit account access logs for signs of unauthorized logins or suspicious account modifications (GitHub Advisory, ENISA EUVD).
The vulnerability received coverage from security news outlets including Heise (English edition) and SecurityOnline.info, both highlighting the critical nature of the authentication bypass in default phpBB installations (Heise, SecurityOnline). The Hacker Wire published a dedicated article on the account hijacking risk (The Hacker Wire). Social media discussion appeared on Mastodon and via ThreatCluster, with the vulnerability also discussed in the phpBB community forums and cross-posted to Veeam and other technical forums (phpBB Forum). CTI Pilot included the vulnerability in its weekly threat brief for W25 2026, noting the structural risk to education and CMS/forum software stacks (CTI Pilot).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."