Cross-Site Request Forgery Vulnerability in uBB.threads by uBB Central
CVE-2026-54220
8.6HIGH
What is CVE-2026-54220?
The uBB.threads software, developed by uBB Central, is susceptible to a Cross-Site Request Forgery (CSRF) attack due to inadequate protective measures. This vulnerability enables malicious actors to exploit an authenticated user’s session, manipulating them into performing unintended actions without their consent. While confirmed in version 7.7.5, it is advisable to assess other versions for similar vulnerabilities.
Affected Version(s)
UBB.threads 0 <= 7.7.5
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kamil Szczurowski (Securitum)
Michał Wnękowicz (Securitum)
