CVE Tools
Back to feed
Patch released phpBB 3.x auth-bypass phpBB 4.0.0 alpha phpBB web-app

Thousands of phpBB Forums Exposed by Critical Authentication Bypass

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

phpBB has disclosed a critical authentication bypass, tracked as CVE-2026-48611, that can allow an unauthenticated attacker to log in as arbitrary users (including administrators) by abusing phpBB’s OAuth-related session handling. The flaw affects phpBB versions up to and including 3.3.16, and the 4.0.0 alpha branch, meaning many installations are exposed by default. This is a severe risk because it enables account takeover via a crafted request, and administrators should update to 3.3.17 (or apply the official mitigations/workarounds) as an urgent priority.