CVE-2026-48611: Phpbb

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

Affected products

  • Phpbb Phpbb: from 3.3.0, up to and including 3.3.16

Published 2026-06-12. Last modified 2026-06-17.