Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-48611] Authentication Bypass in the default configuration phpBB

Summary

CVE-2026-48611 allows an unauthenticated attacker to log in as an arbitrary phpBB user, including an administrator, with a single request on default configurations. phpBB fixed the critical issue in 3.3.17.

Why it matters

A single unauthenticated request can impersonate any phpBB user, including administrators, on default configurations. Upgrading to phpBB 3.3.17 is urgent.
Vendor
phpBB
Product
phpBB
Affected versions
phpBB <= 3.3.16; fixed in 3.3.17
Published
Collected

original ↗

Related coverage

back