CVE Tools

Thousands of phpBB Forums Exposed by Critical Authentication Bypass

Daily CyberSecurity (securityonline.info)By Do Son

PatchphpBB 3.xphpBB 4.0.0 alpha

Our summary

phpBB has disclosed a critical authentication bypass, tracked as CVE-2026-48611, that can allow an unauthenticated attacker to log in as arbitrary users (including administrators) by abusing phpBB’s OAuth-related session handling. The flaw affects phpBB versions up to and including 3.3.16, and the 4.0.0 alpha branch, meaning many installations are exposed by default. This is a severe risk because it enables account takeover via a crafted request, and administrators should update to 3.3.17 (or apply the official mitigations/workarounds) as an urgent priority.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store