CVE-2026-61511: vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5TemplateRuntime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vBulletinto a version that resolves this vulnerability.Fixed in 5.7.5Patch vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61511?
CVE-2026-61511 has a critical severity rating of 9.8.
How do I fix CVE-2026-61511?
To fix CVE-2026-61511, upgrade vBulletin to version 6.2.2 or later.
What impact does CVE-2026-61511 have on my system?
CVE-2026-61511 allows unauthenticated remote attackers to execute arbitrary PHP code, leading to potential full system compromise.
Which versions of vBulletin are affected by CVE-2026-61511?
CVE-2026-61511 affects vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1.
Can I be attacked via CVE-2026-61511 without user authentication?
Yes, CVE-2026-61511 allows remote code execution without requiring user authentication.