CIVN-2026-0391] Arbitrary Code Vulnerability in vBulletin

By Published On: August 6, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Arbitrary Code Vulnerability in vBulletin


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


vBulletin versions from 5.0.0 through 5.7.5

vBulletin versions from 6.0.0 through 6.2.1

Overview


A vulnerability has been reported in vBulletin which could allow an unauthenticated remote attacker to execute arbitrary PHP code on the targeted system.


Target Audience:

All end-user organizations and individuals using VBulletin.


Impact Assessment:

Potential of complete compromise of system


Risk Assessment:

Remote unauthenticated exploitation may lead to complete system compromise.


Description


vBulletin is a commercial PHP-based forum software used to create and manage online discussion boards and community websites.


A vulnerability has been reported in vBulletin due to improper sanitization of user-supplied input in the runMaths() function, an unauthenticated attacker can exploit the flaw by sending a specially crafted request to the ‘ajax/render/[template]’ endpoint.


Successful exploitation of the vulnerability could allow an unauthenticated remote attacker to execute arbitrary PHP code on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor

https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available



Vendor Information


vBulletin

https://www.vbulletin.com/


References


 

https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/


CVE Name

CVE-2026-61511




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp0lqMACgkQ3jCgcSdc

ys+AtQ/+OfOY7NaSPaCU92qx2lNpY31Yj6/APP1AsJlfDyKCwu74uJMmX4INjY0R

RmBZDSN4u5MCymUx1di7jeDOyrXXN3lLzomQBF8yLfgbO5C2n89D+3fvWdFRxVqM

bwI4DkFFjDOID/aLiCDXivYbVkOvUKK3x+WqERsiRF87ceIjbMr3UeQDw2QZ8HsC

HEKWXks+bO9Pti62dQwYEzkMK2GT15KqNStjYMqhvyhO+Sb6UNW6oE4dUuSaUwA2

SZwsD7Eijs7+OTxvXnBdrrpUH37aunBgEPFBu+elaOfBg3twlwQ7vFRs/Hbw6sdu

G27PyTYRgU52+/eCcOGfapkq+dgpJB+eTitxU41OL1J0UhRNxBz1agK/2YORKl32

jhjkdEKa0Svetgzj38Smf+VmmdrArEI5dvkifu2ntgt8XXW7XFohB+5S51i2K64X

zRLPJgMjqoGm46LY9OQPyelbfknyLq8zdrOrtV/LYeghlycX76jzb+NqVVcuO0vu

A0dMB+Z9jvCcMlJFpbx03nhMRVqiL4skFsiCbr/VcVCbAUYtyaIsRVvMce3wCsUH

ZdtxXHGZsyuhjtRsiYZpWp4RvhqyMUyB8piLHb0lDCWy5kr0vZ23tZmICD0grKX8

hakD4slaYNyQNk6R/AE+k01YDC6EGL+BZTxW4LbBnWBfZNqiY58=

=SgsI

—–END PGP SIGNATURE—–

Share this article