logo

Critical CVE-2026-48611 Vulnerability Allows OAuth Account Hijacking

ID: 50a60683-7473-5634-acb5-3aa67c0028ef

STIX ID: report--50a60683-7473-5634-acb5-3aa67c0028ef

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

...
...

CVE-2026-48611 is a critical (CVSS 9.8) vulnerability in phpBB versions before 3.3.16 due to improper OAuth authentication checks that can lead to account hijacking even when OAuth is disabled; maintainers recommend applying the GitHub Advisory patch immediately or disabling OAuth and auditing access logs, and there is currently no public proof-of-concept or reported active exploitation (published June 12, 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.