CVE 9.8 CRITICAL

CVE-2026-48611_CVE-2026-48611

9.8 / 10
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

AI Analysis

OAuth authentication bypass vulnerability allowing account hijacking

Basic Information

ID CVE-2026-48611
Source hackerone
Published Jun 12, 2026 at 02:27
Modified Dec 1, 2026 at 02:27

Affected Product

Vendor phpBB
Product phpBB
Version 3.3.0
Affected Versions phpBB phpBB 3.3.0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor phpBB
Product phpBB
Version 3.3.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.