← Back to browse · API

CVE-2026-48611

Severity
CRITICAL
CVSS
9.8
EPSS
0.0386
Risk score
40.55
CISA KEV
No
PoC
Yes
Published
2026-06-12
Modified
2026-06-12
First seen
2026-08-07
Aliases
EUVD-2026-36375, GHSA-24PR-8GGP-H88C
Products
phpBB:phpBB 3.3.0 ≤3.3.16
Sources
packetstorm 34145f477f06b62717bd3b9e|CVE-2026-48611
euvd EUVD-2026-36375

Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

References