ICYMI, our hashtag#vulnerabilityresearch team found 2 vulnerabilities in phpBB that let an attacker walk in _without_ a password:
_CVE-2026-48611 (9.4): one unauthenticated request, any account, including admin. Default installations. No user interaction. Went unnoticed for over a *decade*.
_CVE-2026-48612 (8.3): if OAuth is configured, an attacker can silently bind their credentials to a logged-in user's account. No click needed from the victim. A hidden image tag in a post is enough.
Full technical write-up, potential impact & detection guidance 👇👇👇
https://pentest-tools.com/research/phpbb-authentication-bypass
hashtag#infosec hashtag#ethicalhacking







