Junglewise Threat Intelligence

CVE-2026-48611: phpBB improper authentication in OAuth implementation

CVE-2026-48611 · Severity: critical · CVSS 9.8 · Published 2026-06-12

Technologies: Phpbb. Vendors: Phpbb.

Executive brief

A critical security flaw has been identified in phpBB, a popular open-source forum software. This vulnerability allows attackers to take over user accounts by bypassing security checks in the login system. Notably, the risk exists even if the forum administrator has not enabled or configured third-party login options like OAuth, potentially leading to a full compromise of the forum and its user data.

Technical details

A vulnerability classified as Improper Authentication (CWE-287) exists within the OAuth implementation of phpBB. The flaw is rooted in insufficient validation during the authentication process, which can be exploited to hijack user accounts. This issue is particularly severe because it affects default installations and remains exploitable even if OAuth functionality is disabled or unconfigured in the administrative settings. An unauthenticated remote attacker can exploit this over the network with low complexity and no user interaction to gain full unauthorized access to accounts.

Affected products

  • phpBB phpBB

Timeline

  • 2026-06-12: disclosed: CVE published to NVD via HackerOne report

References