8
/ 10
HIGH
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Description
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
Basic Information
ID
CVE-2026-48612
Source
hackerone
Published
Jun 12, 2026 at 02:27
Affected Product
Vendor
phpBB
Product
phpBB
Version
3.3.0
Affected Versions
phpBB phpBB 3.3.0