Vulnerability Description
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcement
- https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcement
- https://karmainsecurity.com/KIS-2026-13
- https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
- https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-templa
- http://seclists.org/fulldisclosure/2026/Aug/29
FAQ
What is CVE-2026-61511?
CVE-2026-61511 is a vulnerability with a CVSS score of 9.8 (CRITICAL). vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote...
How severe is CVE-2026-61511?
CVE-2026-61511 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-61511?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.