CVE-2026-48611

CRITICAL EXPLOITED NUCLEI

phpBB < 3.3.16 - Improper Authentication

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2026-48611 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including wanmywan, Diznev, citruscitruscitruscitruscitrusci. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in phpBB (CVE-2026-48611) by leveraging a crafted POST request with Basic Auth to manipulate session cookies and impersonate administrative users. The PoC targets the 'apache' auth provider and specific UCP parameters to achieve unauthorized access.

Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

Exploits (3)

github WORKING POC
by wanmywan · pythonremote
https://github.com/wanmywan/CVE-2026-48611-phpBB

This exploit demonstrates an authentication bypass vulnerability in phpBB (CVE-2026-48611) by leveraging a crafted POST request with Basic Auth to manipulate session cookies and impersonate administrative users. The PoC targets the 'apache' auth provider and specific UCP parameters to achieve unauthorized access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: phpBB 3.3.16 and below, 4.0.0-a2
No auth needed
Prerequisites: Target must have the 'apache' auth provider enabled · Attacker must know a valid username (e.g., 'admin') · User-Agent must match the target's expected value (configurable in script)
mistral-large-3 · analyzed Jul 07, 2026 Full analysis →
github SUSPICIOUS
by Diznev · poc
https://github.com/Diznev/CVE-2026-48611-EXPLOIT

The repository claims to offer a working exploit for CVE-2026-48611 (phpBB OAuth account hijacking) but provides no actual code, only a sales pitch with vague features and external payment links. No technical details or proof of functionality are included.

Classification
Suspicious 95%
Attack Type
Auth Bypass
Complexity
Theoretical
Reliability
Theoretical
Target: phpBB 3.3.0 to 3.3.16 with OAuth enabled
No auth needed
Prerequisites: phpBB with OAuth enabled (Google, Facebook, Bitly)
mistral-large-3 · analyzed Jun 19, 2026 Full analysis →
github WORKING POC
by citruscitruscitruscitruscitrusci · javascriptremote
https://github.com/citruscitruscitruscitruscitrusci/CVE-2026-48611-poc

This PoC demonstrates an authentication bypass vulnerability in a web application by exploiting improper handling of the 'auth_provider' parameter in the login process. It sends a crafted POST request with Basic Auth headers to bypass authentication.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Unknown (likely a PHP-based web application, possibly a forum or CMS)
No auth needed
Prerequisites: Access to the target application's login page · JavaScript execution context (e.g., browser console)
mistral-large-3 · analyzed Jun 14, 2026 Full analysis →

Nuclei Templates (1)

phpBB < 3.3.17 - Authentication Bypass
CRITICALVERIFIEDby aikido,DhiyaneshDk
Shodan: http.component:"phpBB"
FOFA: app="phpBB"

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0386
EPSS Percentile 89.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-07-20
CWE
CWE-287
Status published
Products (1)
phpBB/phpBB 3.3.0 - 3.3.16
Published Jun 12, 2026
Tracked Since Jun 12, 2026