CVE-2026-48612
EUVD-2026-3638012.06.2026, 04:17
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| phpbb | phpbb | 3.3.0 ≤ 𝑥 ≤ 3.3.16 | CNA |
Common Weakness Enumeration