---
schema: 1
kind: vulnerability
title: "CVE-2026-48611 / CVE-2026-48612 — phpBB: unauthenticated authentication bypass to admin, one HTTP request"
headline: "CVE-2026-48611 / CVE-2026-48612 — phpBB: unauthenticated authentication bypass to admin, one HTTP request"
summary: "Pentest-Tools.com disclosed two authentication flaws in phpBB, the open-source forum software common across European universities, municipalities and community portals (Pentest-Tools.com, 2026-06-08). CVE-2026-48611 (NVD CVSS 9.8) is an improper-authentication flaw in the OAuth implementation that allows …"
discovered_at: "2026-06-16T05:08:59Z"
event_date: 2026-06-08
run_id: 2026-06-16-38d638e1
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - pre-auth
  - patch-available
regions:
  - europe
  - global
sectors:
  - public-sector
  - education
entities: []
cves:
  - id: CVE-2026-48611
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48612
    cvss: "8.0"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://pentest-tools.com/research/phpbb-authentication-bypass"
    publisher: Pentest-Tools.com research
    role: primary
  - url: "https://www.phpbb.com/community/viewtopic.php?p=16116763"
    publisher: phpBB community announcement
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Upgrade phpBB to 3.3.17 (CVE-2026-48611 / CVE-2026-48612)** on any internet-reachable forum, especially university and municipal deployments; if upgrade is delayed, disable the OAuth integration even when unused."
migrated_from: briefs/2026-06-16.md
---

Pentest-Tools.com disclosed two authentication flaws in **phpBB**, the open-source forum software common across European universities, municipalities and community portals ([Pentest-Tools.com, 2026-06-08](https://pentest-tools.com/research/phpbb-authentication-bypass)). **CVE-2026-48611** (NVD CVSS 9.8) is an improper-authentication flaw in the OAuth implementation that allows account hijacking — including admin accounts — **even when OAuth is not configured**, reachable by a single unauthenticated request given only a target username (publicly visible via the member list) ([NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-48611)). **CVE-2026-48612** (CVSS 8.0) chains improper OAuth state verification with CSRF to hijack a logged-in session on OAuth-enabled boards. Both affect phpBB 3.1.0 through 3.3.16 (a 10-year release span) and 4.0.0-alpha, and are fixed in **phpBB 3.3.17** ([phpBB, 2026-06-06](https://www.phpbb.com/community/viewtopic.php?p=16116763)). The disclosing source does not publish exploit code, and no in-the-wild exploitation is reported yet. Upgrade immediately for any internet-reachable instance; if upgrade is delayed, disable the OAuth integration even if unused.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | 6.5 | n/a | Yes | Yes (ITW) | 20.9.9.2 / 20.12.7.2 / 20.15.4.5 / 20.15.5.3 / 20.18.3.1 / 26.1.1.2 | [Cisco PSIRT](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ) |
| CVE-2026-54420 | LiteSpeed cPanel/WHM plugin | 8.5 | n/a | Yes | Yes (ITW, May 2026) | WHM PlugIn version 5.3.2.1 / plugin 2.4.8 | [LiteSpeed](https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/) |
| CVE-2026-48611 | phpBB 3.1.0–3.3.16, 4.0.0-alpha | 9.8 | n/a | No | No | phpBB 3.3.17 | [Pentest-Tools.com](https://pentest-tools.com/research/phpbb-authentication-bypass) |
| CVE-2026-48612 | phpBB (OAuth-enabled) | 8.0 | n/a | No | No | phpBB 3.3.17 | [Pentest-Tools.com](https://pentest-tools.com/research/phpbb-authentication-bypass) |
