hacker-news · Crawled Jul 27, 2026
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
1 IoCs
Read original article ↗
AI Summary
A public exploit has been released for a patched pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511. The flaw exists in the template engine's runMaths() method, which allows unauthenticated attackers to execute arbitrary PHP code via crafted requests to the ajax/render/pagenav endpoint. Although patches were released in late June and cloud instances are protected, unpatched self-hosted forums remain at risk. The exploit leverages a 'phpfuck'-style technique to bypass character restrictions and achieve code execution without authentication.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | includes/vb5/template/runtime.php | Details → |