Junglewise Threat Intelligence

CVE-2026-48780: Forem authentication bypass via crafted email address

CVE-2026-48780 · Severity: high · CVSS 8.2 · Published 2026-06-16

Executive brief

Forem is an open-source platform used to build online communities. A security flaw allows attackers to use specially formatted email addresses to bypass domain restrictions, such as allowlists or denylists. This could allow unauthorized individuals to gain access to private, invite-only community deployments, potentially exposing sensitive member data.

Technical details

An improper authentication vulnerability (CWE-287) exists in Forem due to insufficient validation of email addresses during the registration or invitation process. Specifically, the application failed to properly handle 'encoded-word' syntax in email addresses, which could be used to bypass domain-based access controls (allowlists/denylists). An unauthenticated remote attacker can exploit this by providing a maliciously crafted email address to gain unauthorized access to invite-only deployments. The vulnerability was addressed in commit a2ab6d4 by implementing a validation check that rejects email addresses containing encoded-word syntax.

Affected products

  • Forem Forem All versions before commit a2ab6d4

Timeline

  • 2026-05-26: patched: Fix committed to repository
  • 2026-06-16: disclosed: NVD publication date

References