Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-48611] 10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums

aikido.dev | vulnerability | Critical | CVE-2026-48611 | #ai-security | #account-takeover | #authentication-bypass

Summary

Aikido's AI pentesting tool Aikido Attack discovered a critical Authentication Bypass vulnerability in the latest version of the forum software phpBB. The vulnerability is exploitable in the default configuration and requires no special knowledge. If you are on version 4.0.0-a2 or 3.3.16 and below, upgrade immediately to master (no safe 4.x release yet) and 3.3.17, respectively, to avoid compromise.
CVSS
9.8
Published
Collected

original ↗

Related coverage

back