Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.phpbb.com/community/viewtopic.php?t=2672170 |
|
History
Fri, 12 Jun 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpbb
Phpbb phpbb |
|
| Vendors & Products |
Phpbb
Phpbb phpbb |
Fri, 12 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Authentication in phpBB OAuth Enables Account Hijacking |
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-06-12T02:27:43.351Z
Reserved: 2026-05-22T15:00:09.276Z
Link: CVE-2026-48611
No data.
Status : Received
Published: 2026-06-12T04:17:08.180
Modified: 2026-06-12T04:17:08.180
Link: CVE-2026-48611
No data.
OpenCVE Enrichment
Updated: 2026-06-12T04:45:05Z
Weaknesses