Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled, leading to unauthorized access in default installations.
An unauthenticated attacker over the network can hijack user accounts and gain unauthorized access to the application, including the ability to read user data, modify account information, and perform actions as the compromised user.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patch available via GitHub Advisory (GHSA-24pr-8ggp-h88c)
Apply the available patch immediately. If patching cannot be performed immediately, consider disabling OAuth functionality if it is not required, or implementing network-level access controls to restrict exposure. Audit account access logs for signs of unauthorized account access or suspicious login activity.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Feedly found the first article mentioning CVE-2026-48611 . See article
NVD published the first details for CVE-2026-48611
A CVSS base score of 9.8 has been assigned.
GitHub Advisories released a security advisory .
[GHSA-24pr-8ggp-h88c] Improper authentication checks in the OAuth implementation allow account hijacki
[GHSA-24pr-8ggp-h88c] Improper authentication checks in the OAuth implementation allow account hijacki
CVE-2026-48611: phpBB < 3.3.16 - Improper Authentication [CRITICAL] CVSS 9.8
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
