Home

Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

PUBLISHED Reserved 2026-05-22 | Published 2026-06-12 | Updated 2026-06-12 | Assigner hackerone




CRITICAL: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-287 Improper Authentication - Generic

Product status

Default status
unaffected

3.3.0 (semver)
affected

References

www.phpbb.com/community/viewtopic.php?t=2672170

cve.org (CVE-2026-48611)

nvd.nist.gov (CVE-2026-48611)

Download JSON