CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
Description
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
In plain language
AI Act nowCVE-2026-61511 lets someone run code on a vBulletin forum without logging in if you’re using vBulletin older than 6.2.2, so you should update quickly.
Unauthenticated remote code execution is possible in vBulletin < 6.2.2 via the template processing logic in vb5/template/runtime.php, where attacker-controlled input reaches PHP’s eval() through the runMaths() handling (exposed via the ajax/render/[template] endpoint).
What to do now
- Check which vBulletin version you run (and confirm it is earlier than 6.2.2).
- If you are running vBulletin < 6.2.2, plan an upgrade to vBulletin 6.2.2 or later as the urgent fix.
- If you cannot upgrade immediately, restrict internet access to the vBulletin render/template endpoints (especially ajax/render/[template]) using firewall/WAF rules until the upgrade is applied.
- After updating, verify your vBulletin version shows 6.2.2 and confirm the site remains reachable normally.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacksen·The Hacker News· Exploited Coldcard Wallet Laundry Bear
- vBulletin fixes critical pre-auth RCE flaw with public exploiten-us·BleepingComputer· PoC vBulletin rce
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flawen·The Hacker News· PoC vBulletin rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61511 and every CVE in our database. Create a free account — no credit card required.
Create Free Account