Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.phpbb.com/community/viewtopic.php?t=2672170 |
|
History
Fri, 12 Jun 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpbb
Phpbb phpbb |
|
| Vendors & Products |
Phpbb
Phpbb phpbb |
Fri, 12 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper OAuth State Verification Allows Account Takeover |
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover. | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-06-12T02:27:43.506Z
Reserved: 2026-05-22T15:00:09.276Z
Link: CVE-2026-48612
No data.
Status : Received
Published: 2026-06-12T04:17:10.123
Modified: 2026-06-12T04:17:10.123
Link: CVE-2026-48612
No data.
OpenCVE Enrichment
Updated: 2026-06-12T04:45:05Z
Weaknesses