PT-2026-48826 · Phpbb · Phpbb

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-48611

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpBB versions prior to 3.3.16
Description Improper authentication checks in the OAuth implementation allow remote unauthenticated account hijacking. This issue can lead to unauthorized access in default installations, even in cases where OAuth is not configured or enabled.
Recommendations Update to version 3.3.16.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-48611

Affected Products

Phpbb