cve-2026-48611

CRITICAL CVSS 9.8 opencve
Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

Timeline
Published
2026-06-12 04:17 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.0 9.8 CRITICAL CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H mitre
3.0 9.8 CRITICAL CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H nvd
3.0 9.8 CRITICAL CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-48611",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[3.3.0,3.3.16]"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "matching",
          "scores": [
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "phpBB",
          "source": "cna",
          "vendor": "phpBB"
        },
        "product": "phpbb",
        "vendor": "phpbb"
      }
    ],
    "created": "2026-06-12T04:30:04.781867+00:00",
    "title": "OAuth Authentication Bypass Allows Account Hijacking in phpBB",
    "updated": "2026-07-31T17:15:03.773392+00:00",
    "vendors": [
      "phpbb",
      "phpbb$PRODUCT$phpbb"
    ]
  },
  "epss": {
    "score": 0.02888
  },
  "mitre": {
    "cpes": [],
    "created": "2026-06-12T02:27:43.351000+00:00",
    "description": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {
        "score": 9.8,
        "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/48xxx/CVE-2026-48611.json",
    "references": [
      "https://www.phpbb.com/community/viewtopic.php?t=2672170"
    ],
    "title": null,
    "updated": "2026-06-12T12:55:19.663000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-287"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2026-06-12T04:17:08.180000+00:00",
    "description": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {
        "score": 9.8,
        "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-48611.json",
    "references": [
      "https://www.phpbb.com/community/viewtopic.php?t=2672170"
    ],
    "title": null,
    "updated": "2026-06-17T10:55:09.423000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-287"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-06-12T03:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "added": [
                "CWE-287"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://www.phpbb.com/community/viewtopic.php?t=2672170"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_0": {
                  "score": 9.8,
                  "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "62adc9df-87f4-47d0-af6e-9bed5c1ed860"
      },
      {
        "created": "2026-06-12T04:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Improper Authentication in phpBB OAuth Enables Account Hijacking",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "ab6b592b-89fc-48ab-97c7-a4b7156f1629"
      },
      {
        "created": "2026-06-12T05:00:00+00:00",
        "data": [
          {
            "details": [
              "phpbb",
              "phpbb$PRODUCT$phpbb"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "phpbb",
                "phpbb$PRODUCT$phpbb"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "9252eb2d-d1d4-45fe-a4b1-aced5325982c"
      },
      {
        "created": "2026-06-12T13:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "c6398d85-50c7-4b77-95fe-c78d17c85391"
      },
      {
        "created": "2026-07-08T20:45:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Improper Authentication in phpBB OAuth Enables Account Hijacking"
            },
            "type": "title"
          }
        ],
        "id": "bcfca8ab-4a24-4edc-b40e-aa2d0e79cf21"
      },
      {
        "created": "2026-07-09T15:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "OAuth Authentication Bypass Enables Account Hijacking in phpBB",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "2e935c28-58d8-4d9e-9ce1-be0b0e15e8a7"
      },
      {
        "created": "2026-07-11T03:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "OAuth Authentication Bypass Enables Account Hijacking in phpBB"
            },
            "type": "title"
          }
        ],
        "id": "e6348d29-ded8-4c63-a5bc-d059eb6ac33d"
      },
      {
        "created": "2026-07-12T03:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Account Hijacking via Unconditional OAuth Authentication Bypass in phpBB",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "28cbae0d-ca7a-4b61-92c2-d606e40c35ec"
      },
      {
        "created": "2026-07-14T02:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Account Hijacking via Unconditional OAuth Authentication Bypass in phpBB"
            },
            "type": "title"
          }
        ],
        "id": "9264fd8d-7117-4f4d-a748-0e99eb1048c4"
      },
      {
        "created": "2026-07-17T16:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "OAuth Authentication Bypass Allowing Account Hijacking in phpBB",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "84867b06-40df-43c1-86c4-7778f9e15441"
      },
      {
        "created": "2026-07-23T21:45:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "OAuth Authentication Bypass Allowing Account Hijacking in phpBB"
            },
            "type": "title"
          }
        ],
        "id": "a1bdd48d-2a79-49ba-9698-939015457e99"
      },
      {
        "created": "2026-07-31T17:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "OAuth Authentication Bypass Allows Account Hijacking in phpBB",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "adbf3dc5-ff07-4aa1-9309-387016a14a40"
      }
    ],
    "cpes": {
      "data": [],
      "providers": []
    },
    "created": {
      "data": "2026-06-12T02:27:43.351000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {
          "score": 9.8,
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV3_1": {
        "data": {},
        "provider": null
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.02888
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.phpbb.com/community/viewtopic.php?t=2672170"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "OAuth Authentication Bypass Allows Account Hijacking in phpBB",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-07-31T17:15:03.773392+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "phpbb",
        "phpbb$PRODUCT$phpbb"
      ],
      "providers": [
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-287"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-06-12T02:27:43.351000+00:00",
    "description": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-06-12T12:55:16.484000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/48xxx/CVE-2026-48611.json",
    "weaknesses": []
  }
}
Enrichment data
Nuclei templates
Aggregated bundle (all enrichments)
View JSON API Download JSON