CVE-2026-48611
Description
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
In plain language
AI Worth attentionCVE-2026-48611 is a serious phpBB login/account takeover issue that can affect even default installs, so you should act soon and get to the patched version.
What to do
- Update phpBB to the patched version your vendor provides for CVE-2026-48611. 2) If you can’t update immediately, ask your IT person to confirm whether your current OAuth/account-related code paths are affected and apply any vendor-recommended mitigations. 3) Check with whoever maintains your phpBB for the specific upgrade target and document when you applied it.
CVSS Vector Breakdown
Exploitability
AV:NAttack VectorNetwork
AC:LAttack ComplexityLow
PR:NPrivileges RequiredNone
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:HConfidentialityHigh
I:HIntegrityHigh
A:HAvailabilityHigh
Weaknesses
Affected Products
phpBB
oss-project
Exploitability
No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.
Attack Graph
Products CVE Techniques Tactics
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniques Initial Access
References
News mentions
2Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48611 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
