Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-48611 [Critical]

Curated 2 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-48611.

Vendor
phpBB
Product
phpBB
Affected versions
phpBB <= 3.3.16; fixed in 3.3.17
CVSS
9.8
Coverage Span
2026-06-10 → 2026-07-04
Reports
2 related reports

Associated Reports & Timeline

1.
aikido.dev | vulnerability | Critical | | original ↗ | #ai-security | #featured | #account-takeover | #authentication-bypass
CVE-2026-48611 allows an unauthenticated attacker to log in as an arbitrary phpBB user, including an administrator, with a single request on default configurations. phpBB fixed the critical issue in 3.3.17.
Why it matters: A single unauthenticated request can impersonate any phpBB user, including administrators, on default configurations. Upgrading to phpBB 3.3.17 is urgent.