CVE-2026-48611
CRITICAL EXPLOITED NUCLEIphpBB < 3.3.16 - Improper Authentication
Title source: ruleExploitation Summary
CVE-2026-48611 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including wanmywan, Diznev, citruscitruscitruscitruscitrusci. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in phpBB (CVE-2026-48611) by leveraging a crafted POST request with Basic Auth to manipulate session cookies and impersonate administrative users. The PoC targets the 'apache' auth provider and specific UCP parameters to achieve unauthorized access.
Description
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Exploits (3)
This exploit demonstrates an authentication bypass vulnerability in phpBB (CVE-2026-48611) by leveraging a crafted POST request with Basic Auth to manipulate session cookies and impersonate administrative users. The PoC targets the 'apache' auth provider and specific UCP parameters to achieve unauthorized access.
The repository claims to offer a working exploit for CVE-2026-48611 (phpBB OAuth account hijacking) but provides no actual code, only a sales pitch with vague features and external payment links. No technical details or proof of functionality are included.
This PoC demonstrates an authentication bypass vulnerability in a web application by exploiting improper handling of the 'auth_provider' parameter in the login process. It sends a crafted POST request with Basic Auth headers to bypass authentication.
Nuclei Templates (1)
http.component:"phpBB"
app="phpBB"
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H