PT-2026-48826 · Phpbb · Phpbb
CVE-2026-48611
·
Published
2026-06-12
·
Updated
2026-07-20
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpBB versions prior to 3.3.17
Description
Improper authentication checks in the OAuth implementation allow for account hijacking and unauthorized access in default installations, even if OAuth is not configured or enabled. This authentication bypass allows an unauthenticated attacker to log in as any user, including administrators, using a single HTTP request without requiring a password. Real-world exploitation attempts have been detected, and over 10,000 potentially affected devices have been identified via FOFA.
Recommendations
Update phpBB to version 3.3.17.
Fix
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpbb