Skip to content
CVE-2026-48611 - Exploits & Severity

CVE-2026-48611 - Exploits & Severity

Feedly June 12, 2026

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled, leading to unauthorized access in default installations.

An unauthenticated attacker over the network can hijack user accounts and gain unauthorized access to the application, including the ability to read user data, modify account information, and perform actions as the compromised user.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch available via GitHub Advisory (GHSA-24pr-8ggp-h88c)

Apply the available patch immediately. If patching cannot be performed immediately, consider disabling OAuth functionality if it is not required, or implementing network-level access controls to restrict exposure. Audit account access logs for signs of unauthorized account access or suspicious login activity.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Feedly found the first article mentioning CVE-2026-48611 . See article

NVD published the first details for CVE-2026-48611

A CVSS base score of 9.8 has been assigned.

GitHub Advisories released a security advisory .

[GHSA-24pr-8ggp-h88c] Improper authentication checks in the OAuth implementation allow account hijacki

[GHSA-24pr-8ggp-h88c] Improper authentication checks in the OAuth implementation allow account hijacki

CVE-2026-48611: phpBB < 3.3.16 - Improper Authentication [CRITICAL] CVSS 9.8

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities