
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48612 is an improper state verification vulnerability in the OAuth implementation of phpBB (versions 3.3.0 through 3.3.16) that allows an attacker to manipulate the authentication flow and link a victim's account to an attacker-controlled account, resulting in unauthorized account takeover. The vulnerability was published on June 12, 2026, and was assigned by HackerOne. It carries a CVSS v3.0 base score of 8.0 (High) (GitHub Advisory, ENISA EUVD).
The root cause is improper state parameter verification in phpBB's OAuth implementation (CWE-352: Cross-Site Request Forgery), where the application fails to adequately validate the state parameter during the OAuth authorization callback. An attacker with low privileges can craft a malicious OAuth flow that, when a victim interacts with it (e.g., by clicking a link), causes the victim's phpBB account to be linked to an OAuth identity controlled by the attacker. Exploitation requires network access, low privileges, high attack complexity, and victim user interaction. A technical write-up is available from Pentest Tools (Pentest Tools) and the phpBB community forum (phpBB Forum).
Successful exploitation enables unauthorized account linking and full account takeover of the victim's phpBB account, granting the attacker high confidentiality, integrity, and availability impact over the compromised account. An attacker who gains control of a victim's account — particularly an administrator account — could access private messages, sensitive forum data, and potentially escalate to administrative control of the phpBB installation. The changed scope indicator reflects that the impact extends beyond the attacker's own account to affect the victim's resources (GitHub Advisory, ENISA EUVD).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.023% (0.12% per GitHub Advisory), placing it in the 2nd percentile for exploitation likelihood within 30 days. The CVE status is listed as "Deferred" and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
state parameter from the authorization URL.state parameter from their own OAuth session but intended to be triggered by the victim (e.g., via a phishing link or CSRF-triggering page).state parameter corresponds to the victim's own OAuth session, the callback is processed and the victim's phpBB account is linked to the attacker's OAuth identity.oauth_link or equivalent) for a user account that was not initiated by that user; multiple OAuth callback requests from different IP addresses for the same state parameter.GET /ucp.php?mode=login&login=external&oauth_service=...) originating from IP addresses not associated with the legitimate user's session.Administrators should update phpBB to a version beyond 3.3.16 once a patched release is made available by the phpBB team; the advisory references the phpBB community forum for patch details (phpBB Forum). As an interim workaround, disabling OAuth-based social login features in phpBB's authentication settings will eliminate the attack surface. Additionally, implementing PKCE (Proof Key for Code Exchange) and binding the OAuth state parameter to the user's session server-side are recommended hardening measures (GitHub Advisory).
Heise (a major German IT news outlet) covered the vulnerability, describing it as a critical security issue allowing compromise of phpBB installations (Heise). The CTI Pilot threat intelligence platform published a brief characterizing the combined CVE-2026-48611 and CVE-2026-48612 issues as "unauthenticated authentication bypass to admin" in phpBB (CTI Pilot). INCIBE-CERT (Spain's national cybersecurity incident response center) also issued an early warning advisory for the vulnerability (INCIBE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."