CVE-2026-61511, a critical remote code execution flaw, allows unauthenticated attackers to execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The vulnerability exists in the application's template processing functionality, specifically within the component responsible for evaluating mathematical expressions used by a custom template tag. The filtering mechanism is inadequate, allowing characters such as digits, parentheses, arithmetic operators, binary operators, and the XOR operator to be processed as PHP code. This enables attackers to leverage 'PHPFuck' techniques to construct function names and commands without directly using blocked alphabetic characters. Exploiting this vulnerability does not require administrator access, allowing attackers to execute operating-system commands under the permissions of the web server process, resulting in data theft, website defacement, malware deployment, credential harvesting, or lateral movement within the hosting environment. Public-facing vBulletin forums should be prioritized for patching since exploitation can occur without authentication.
The following reports contain further technical details:[/subscribe_to_unlock_form]
CVE-2026-61511, a critical remote code execution flaw, allows unauthenticated attackers to execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The vulnerability exists in the application's template processing functionality, specifically within the component responsible for evaluating mathematical expressions used by a custom template tag. The filtering mechanism is inadequate, allowing characters such as digits, parentheses, arithmetic operators, binary operators, and the XOR operator to be processed as PHP code. This enables attackers to leverage 'PHPFuck' techniques to construct function names and commands without directly using blocked alphabetic characters. Exploiting this vulnerability does not require administrator access, allowing attackers to execute operating-system commands under the permissions of the web server process, resulting in data theft, website defacement, malware deployment, credential harvesting, or lateral movement within the hosting environment. Public-facing vBulletin forums should be prioritized for patching since exploitation can occur without authentication.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]