[CVE-2026-48611] 10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums
aikido.dev | vulnerability | Critical | CVE-2026-48611 | #ai-security | #account-takeover | #authentication-bypass
Summary
Aikido's AI pentesting tool Aikido Attack discovered a critical Authentication Bypass vulnerability in the latest version of the forum software phpBB. The vulnerability is exploitable in the default configuration and requires no special knowledge. If you are on version 4.0.0-a2 or 3.3.16 and below, upgrade immediately to master (no safe 4.x release yet) and 3.3.17, respectively, to avoid compromise.
- CVSS
- 9.8
- Published
- Collected
Skip to content