[CVE-2026-48611] Authentication Bypass in the default configuration phpBB
aikido.dev | vulnerability | Critical | CVE-2026-48611 | #ai-security | #featured | #account-takeover | #authentication-bypass | #phpbb | #web-security | #aikido | #vulnerability-disclosure | #oauth | #cve-2026-48611
Summary
CVE-2026-48611 allows an unauthenticated attacker to log in as an arbitrary phpBB user, including an administrator, with a single request on default configurations. phpBB fixed the critical issue in 3.3.17.
Why it matters
A single unauthenticated request can impersonate any phpBB user, including administrators, on default configurations. Upgrading to phpBB 3.3.17 is urgent.
- Vendor
- phpBB
- Product
- phpBB
- Affected versions
- phpBB <= 3.3.16; fixed in 3.3.17
- Published
- Collected
Skip to content