CVE-2026-48611

Confirmed PUBLISHED

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to...

phpBB · phpBB

Not yet in CISA KEV

Exploited in the wild Active exploitation observed PoC available

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
1
Unique Attacker IPs
1
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.8 Critical EPSS 2.9%

At a Glance

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

php nuclei_scanner
CVE Published
Jun 12, 2026
Exploitation Reported
Jul 19, 2026
CVSS
9.8 Critical
EPSS
2.9%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
phpBB
phpBB

3.3.0 to <= 3.3.16

Affected

CVE References

Recommended Actions

  • Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.
  • Review sensor telemetry for request paths, attacker IPs, and payload patterns that may inform detection and exposure validation.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.