CVE-2026-48612: Phpbb
High severity, CVSS 8.0. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
Affected products
- Phpbb Phpbb: from 3.3.0, up to and including 3.3.16
Published 2026-06-12. Last modified 2026-06-17.