Junglewise Threat Intelligence

CVE-2026-54220: UBB Systems UBB.threads Cross-Site Request Forgery

CVE-2026-54220 · Severity: info · CVSS 8.6 · Published 2026-06-18

Technologies: UBB Systems UBB.threads. Vendors: UBB Systems.

Executive brief

UBB.threads, a popular forum and community software, contains a security flaw that allows attackers to perform actions on behalf of legitimate users. By tricking a logged-in user (such as an administrator) into clicking a malicious link or visiting a compromised website, an attacker can force the application to execute unauthorized commands. This could lead to unauthorized changes to forum settings, account takeovers, or the deletion of data without the user's knowledge.

Technical details

UBB.threads through version 7.7.5 is vulnerable to Cross-Site Request Forgery (CSRF) because the application lacks anti-CSRF tokens or other protective mechanisms for sensitive state-changing operations. An unauthenticated remote attacker can exploit this by crafting a malicious web page or link and tricking an authenticated user into interacting with it. If successful, the attacker can execute actions in the context of the victim's session, potentially leading to full account compromise or administrative configuration changes. As vendor contact attempts were unsuccessful, no official patch is currently available.

Affected products

  • UBB Systems UBB.threads All through 7.7.5

Timeline

  • 2026-06-18: disclosed: Vulnerability disclosed by CERT Polska after unsuccessful vendor contact attempts.
  • 2026-06-18: advisory

References

Related threats