CVE-2026-48611
published 2026-06-12CVE-2026-48611: Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access…
PriorityP185critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
3.86%
89.5th percentile
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpbb | phpbb | 3.3.0 – 3.3.16 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
ghsa_unreviewed·2026-06-12
CVE-2026-48611 [CRITICAL] CWE-287 Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
VulnCheck
phpbb phpbb Improper Authentication
vulncheck·2026·CVSS 9.8
CVE-2026-48611 [CRITICAL] phpbb phpbb Improper Authentication
phpbb phpbb Improper Authentication
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Affected: phpbb phpbb
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2026-48611; https://www.linkedin.com/posts/cybersecurity-threatintelligence-vulnerabilitymanagement-share-7484884815117406208-XKwV/
Exploit PoC: https://vulncheck.com/xdb/ffb215a40c3f; https://vulncheck.com/xdb/ec492fbb5dcf
No detection rules found.
Nuclei
phpBB < 3.3.17 - Authentication Bypass
nuclei·CVSS 9.8
CVE-2026-48611 [CRITICAL] phpBB < 3.3.17 - Authentication Bypass
phpBB < 3.3.17 - Authentication Bypass
phpBB before 3.3.17 contains an authentication bypass vulnerability in the login-link feature. By setting the auth_provider query parameter to "apache", an unauthenticated attacker can bypass password verification and log in as any user, including administrators. The Apache auth provider trusts the Basic authentication header username without password verification, as it assumes Apache handles authentication upstream.
Template:
id: CVE-2026-48611
info:
name: phpBB < 3.3.17 - Authentication Bypass
author: aikido,DhiyaneshDk
severity: critical
description: |
phpBB before 3.3.17 contains an authentication bypass vulnerability in the login-link feature. By setting the auth_provider query parameter to "apache", an unauthenticated attacker can bypass pa
2026-06-12
Published
Exploited in the wild