Patch released phpBB 3.x auth-bypass phpBB 4.0.0 alpha phpBB web-app
Thousands of phpBB Forums Exposed by Critical Authentication Bypass
CVE Tools coverage
phpBB has disclosed a critical authentication bypass, tracked as CVE-2026-48611, that can allow an unauthenticated attacker to log in as arbitrary users (including administrators) by abusing phpBB’s OAuth-related session handling. The flaw affects phpBB versions up to and including 3.3.16, and the 4.0.0 alpha branch, meaning many installations are exposed by default. This is a severe risk because it enables account takeover via a crafted request, and administrators should update to 3.3.17 (or apply the official mitigations/workarounds) as an urgent priority.