Critical CVE-2026-48611 Vulnerability Allows OAuth Account Hijacking
ID: 50a60683-7473-5634-acb5-3aa67c0028ef
STIX ID: report--50a60683-7473-5634-acb5-3aa67c0028ef
Feed Name: ThreatCluster
Threat Score
CVE-2026-48611 is a critical (CVSS 9.8) vulnerability in phpBB versions before 3.3.16 due to improper OAuth authentication checks that can lead to account hijacking even when OAuth is disabled; maintainers recommend applying the GitHub Advisory patch immediately or disabling OAuth and auditing access logs, and there is currently no public proof-of-concept or reported active exploitation (published June 12, 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
