cve-2026-48611
CRITICAL CVSS 9.8 opencve
Description
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Timeline
- Published
- 2026-06-12 04:17 UTC
- Last Modified
- 2026-06-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.0 | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
mitre | ||
| 3.0 | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.0 | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-48611",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[3.3.0,3.3.16]"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "matching",
"scores": [
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "phpBB",
"source": "cna",
"vendor": "phpBB"
},
"product": "phpbb",
"vendor": "phpbb"
}
],
"created": "2026-06-12T04:30:04.781867+00:00",
"title": "OAuth Authentication Bypass Allows Account Hijacking in phpBB",
"updated": "2026-07-31T17:15:03.773392+00:00",
"vendors": [
"phpbb",
"phpbb$PRODUCT$phpbb"
]
},
"epss": {
"score": 0.02888
},
"mitre": {
"cpes": [],
"created": "2026-06-12T02:27:43.351000+00:00",
"description": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {
"score": 9.8,
"vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/48xxx/CVE-2026-48611.json",
"references": [
"https://www.phpbb.com/community/viewtopic.php?t=2672170"
],
"title": null,
"updated": "2026-06-12T12:55:19.663000+00:00",
"vendors": [],
"weaknesses": [
"CWE-287"
]
},
"nvd": {
"cpes": [],
"created": "2026-06-12T04:17:08.180000+00:00",
"description": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {
"score": 9.8,
"vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV3_1": {},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-48611.json",
"references": [
"https://www.phpbb.com/community/viewtopic.php?t=2672170"
],
"title": null,
"updated": "2026-06-17T10:55:09.423000+00:00",
"vendors": [],
"weaknesses": [
"CWE-287"
]
},
"opencve": {
"changes": [
{
"created": "2026-06-12T03:30:00+00:00",
"data": [
{
"details": {
"new": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
"old": null
},
"type": "description"
},
{
"details": {
"added": [
"CWE-287"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://www.phpbb.com/community/viewtopic.php?t=2672170"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_0": {
"score": 9.8,
"vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "62adc9df-87f4-47d0-af6e-9bed5c1ed860"
},
{
"created": "2026-06-12T04:45:00+00:00",
"data": [
{
"details": {
"new": "Improper Authentication in phpBB OAuth Enables Account Hijacking",
"old": null
},
"type": "title"
}
],
"id": "ab6b592b-89fc-48ab-97c7-a4b7156f1629"
},
{
"created": "2026-06-12T05:00:00+00:00",
"data": [
{
"details": [
"phpbb",
"phpbb$PRODUCT$phpbb"
],
"type": "first_time"
},
{
"details": {
"added": [
"phpbb",
"phpbb$PRODUCT$phpbb"
],
"removed": []
},
"type": "vendors"
}
],
"id": "9252eb2d-d1d4-45fe-a4b1-aced5325982c"
},
{
"created": "2026-06-12T13:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "c6398d85-50c7-4b77-95fe-c78d17c85391"
},
{
"created": "2026-07-08T20:45:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Improper Authentication in phpBB OAuth Enables Account Hijacking"
},
"type": "title"
}
],
"id": "bcfca8ab-4a24-4edc-b40e-aa2d0e79cf21"
},
{
"created": "2026-07-09T15:45:00+00:00",
"data": [
{
"details": {
"new": "OAuth Authentication Bypass Enables Account Hijacking in phpBB",
"old": null
},
"type": "title"
}
],
"id": "2e935c28-58d8-4d9e-9ce1-be0b0e15e8a7"
},
{
"created": "2026-07-11T03:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "OAuth Authentication Bypass Enables Account Hijacking in phpBB"
},
"type": "title"
}
],
"id": "e6348d29-ded8-4c63-a5bc-d059eb6ac33d"
},
{
"created": "2026-07-12T03:45:00+00:00",
"data": [
{
"details": {
"new": "Account Hijacking via Unconditional OAuth Authentication Bypass in phpBB",
"old": null
},
"type": "title"
}
],
"id": "28cbae0d-ca7a-4b61-92c2-d606e40c35ec"
},
{
"created": "2026-07-14T02:00:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Account Hijacking via Unconditional OAuth Authentication Bypass in phpBB"
},
"type": "title"
}
],
"id": "9264fd8d-7117-4f4d-a748-0e99eb1048c4"
},
{
"created": "2026-07-17T16:00:00+00:00",
"data": [
{
"details": {
"new": "OAuth Authentication Bypass Allowing Account Hijacking in phpBB",
"old": null
},
"type": "title"
}
],
"id": "84867b06-40df-43c1-86c4-7778f9e15441"
},
{
"created": "2026-07-23T21:45:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "OAuth Authentication Bypass Allowing Account Hijacking in phpBB"
},
"type": "title"
}
],
"id": "a1bdd48d-2a79-49ba-9698-939015457e99"
},
{
"created": "2026-07-31T17:30:00+00:00",
"data": [
{
"details": {
"new": "OAuth Authentication Bypass Allows Account Hijacking in phpBB",
"old": null
},
"type": "title"
}
],
"id": "adbf3dc5-ff07-4aa1-9309-387016a14a40"
}
],
"cpes": {
"data": [],
"providers": []
},
"created": {
"data": "2026-06-12T02:27:43.351000+00:00",
"provider": "mitre"
},
"description": {
"data": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {
"score": 9.8,
"vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV3_1": {
"data": {},
"provider": null
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.02888
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.phpbb.com/community/viewtopic.php?t=2672170"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "OAuth Authentication Bypass Allows Account Hijacking in phpBB",
"provider": "enrichment"
},
"updated": {
"data": "2026-07-31T17:15:03.773392+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"phpbb",
"phpbb$PRODUCT$phpbb"
],
"providers": [
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-287"
],
"providers": [
"mitre",
"nvd"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-06-12T02:27:43.351000+00:00",
"description": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-06-12T12:55:16.484000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/48xxx/CVE-2026-48611.json",
"weaknesses": []
}
}
Enrichment data
Aggregated bundle (all enrichments)