Description
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Published: 2026-06-12
Score: 9.8 Critical
EPSS: 2.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is caused by inadequate authentication checks in phpBB's OAuth feature, allowing an attacker to acquire a user session even when the OAuth component is not configured or actively enabled. This authentication bypass (CWE-287) lets an attacker impersonate any forum account, read private messages, modify posts, depending on the target account's role. The vulnerability can be triggered by sending crafted HTTP requests to the application.

Affected Systems

Any phpBB forum running a default installation with OAuth not disabled is at risk. No specific affected versions are documented—any release that has not been patched is potentially vulnerable.

Risk and Exploitability

The vulnerability's severity is reflected by a CVSS score of 9.8, indicating a critical risk. The EPSS score of 3% suggests that, while the flaw is unlikely to be widely attacked yet, the possibility of exploitation remains. No entry in CISA KEV means it has not yet been observed in the wild, but the lack of a public exploit does not reduce its danger. An attacker can exploit the issue remotely via ordinary HTTP traffic, with no need for special permissions or elevated credentials.

Generated by OpenCVE AI on July 17, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for phpBB to address the OAuth authentication bypass.
  • If an immediate patch is not available, disable the OAuth module in phpBB's configuration to prevent exploitation.
  • After remediation, monitor authentication logs for anomalous login attempts and verify that no unauthorized account activity occurs.

Generated by OpenCVE AI on July 17, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title OAuth Authentication Bypass Allowing Account Hijacking in phpBB

Tue, 14 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Account Hijacking via Unconditional OAuth Authentication Bypass in phpBB

Sun, 12 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Account Hijacking via Unconditional OAuth Authentication Bypass in phpBB

Sat, 11 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title OAuth Authentication Bypass Enables Account Hijacking in phpBB

Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title OAuth Authentication Bypass Enables Account Hijacking in phpBB

Wed, 08 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Authentication in phpBB OAuth Enables Account Hijacking

Fri, 12 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Phpbb
Phpbb phpbb
Vendors & Products Phpbb
Phpbb phpbb

Fri, 12 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper Authentication in phpBB OAuth Enables Account Hijacking

Fri, 12 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
Description Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Weaknesses CWE-287
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-06-12T12:55:19.663Z

Reserved: 2026-05-22T15:00:09.276Z

Link: CVE-2026-48611

cve-icon Vulnrichment

Updated: 2026-06-12T12:55:16.484Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T04:17:08.180

Modified: 2026-06-12T16:15:57.387

Link: CVE-2026-48611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:45:05Z

Weaknesses