Home

Description

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.

PUBLISHED Reserved 2026-05-22 | Published 2026-06-12 | Updated 2026-06-12 | Assigner hackerone




HIGH: 8.0CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Default status
unaffected

3.3.0 (semver)
affected

References

www.phpbb.com/community/viewtopic.php?t=2672170

cve.org (CVE-2026-48612)

nvd.nist.gov (CVE-2026-48612)

Download JSON