# Authentication Bypass in the default configuration phpBB

DevFeed: [Authentication Bypass in the default configuration phpBB](<https://devfeed.tech/articles/authentication-bypass-in-the-default-configuration-phpbb-51604.md>)

Original publisher: [Read original article](<https://www.aikido.dev/blog/authentication-bypass-phpbb-technical-writeup>)

Author: Jorian Woltjer

Published: 2026-07-03T23:45:00Z

Content type: article

Language: en

Sources: [Aikido Security's Blog](<https://devfeed.tech/sources/aikido-security-s-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [callback](<https://devfeed.tech/topics/callback.md>), [Query (disambiguation)](<https://devfeed.tech/topics/query.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authentication-bypass](<https://devfeed.tech/tags/authentication-bypass.md>), [critical](<https://devfeed.tech/tags/critical.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

A technical write-up describes CVE-2026-48611, a critical authentication bypass in phpBB's default configuration. The flaw allowed an unauthenticated request to log in to any account, including administrator accounts, and was patched in phpBB 3.3.17.

## Source excerpt

Our AI pentest agents found a critical phpBB auth bypass (CVE-2026-48611): one unauthenticated request logs you into any account. See the exploit and the fix. Category: Vulnerabilities & Threats