logo

Thousands of phpBB Forums Exposed by Critical Authentication Bypass

ID: 75053170-43d8-5955-b527-327c2fc0e3ef

STIX ID: report--75053170-43d8-5955-b527-327c2fc0e3ef

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

A critical phpBB OAuth authentication bypass (CVE-2026-48611, CVSS 9.8) lets unauthenticated attackers forge sessions and take over any account — including administrators — on default installations up to 3.3.16 and 4.0.0 alpha. Administrators should upgrade immediately to phpBB 3.3.17 or apply official mitigations and disable OAuth until patched; active probing of exposed forums has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.