hacker-news · Crawled Jul 27, 2026

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

1 IoCs
Read original article ↗

AI Summary

A public exploit has been released for a patched pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511. The flaw exists in the template engine's runMaths() method, which allows unauthenticated attackers to execute arbitrary PHP code via crafted requests to the ajax/render/pagenav endpoint. Although patches were released in late June and cloud instances are protected, unpatched self-hosted forums remain at risk. The exploit leverages a 'phpfuck'-style technique to bypass character restrictions and achieve code execution without authentication.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename includes/vb5/template/runtime.php Details →