9.8
/ 10
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
AI Analysis
OAuth authentication bypass vulnerability allowing account hijacking
Basic Information
ID
CVE-2026-48611
Source
hackerone
Published
Jun 12, 2026 at 02:27
Modified
Dec 1, 2026 at 02:27
Affected Product
Vendor
phpBB
Product
phpBB
Version
3.3.0
Affected Versions
phpBB phpBB 3.3.0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
phpBB
Product
phpBB
Version
3.3.0