Threat Advisory

vBulletin Flaw Lets Attackers Execute Arbitrary PHP Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61511, a critical remote code execution flaw, allows unauthenticated attackers to execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The vulnerability exists in the application's template processing functionality, specifically within the component responsible for evaluating mathematical expressions used by a custom template tag. The filtering mechanism is inadequate, allowing characters such as digits, parentheses, arithmetic operators, binary operators, and the XOR operator to be processed as PHP code. This enables attackers to leverage 'PHPFuck' techniques to construct function names and commands without directly using blocked alphabetic characters. Exploiting this vulnerability does not require administrator access, allowing attackers to execute operating-system commands under the permissions of the web server process, resulting in data theft, website defacement, malware deployment, credential harvesting, or lateral movement within the hosting environment. Public-facing vBulletin forums should be prioritized for patching since exploitation can occur without authentication.

RECOMMENDATIONS:

  • We recommend you to update vBulletin to version 6.2.2.
  • We recommend you to apply the vendor-provided patches for affected versions 6.2.1, 6.2.0, and 6.1.6 of vBulletin.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61511, a critical remote code execution flaw, allows unauthenticated attackers to execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The vulnerability exists in the application's template processing functionality, specifically within the component responsible for evaluating mathematical expressions used by a custom template tag. The filtering mechanism is inadequate, allowing characters such as digits, parentheses, arithmetic operators, binary operators, and the XOR operator to be processed as PHP code. This enables attackers to leverage 'PHPFuck' techniques to construct function names and commands without directly using blocked alphabetic characters. Exploiting this vulnerability does not require administrator access, allowing attackers to execute operating-system commands under the permissions of the web server process, resulting in data theft, website defacement, malware deployment, credential harvesting, or lateral movement within the hosting environment. Public-facing vBulletin forums should be prioritized for patching since exploitation can occur without authentication.

RECOMMENDATIONS:

  • We recommend you to update vBulletin to version 6.2.2.
  • We recommend you to apply the vendor-provided patches for affected versions 6.2.1, 6.2.0, and 6.1.6 of vBulletin.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu