Cross-Site Request Forgery Vulnerability in uBB.threads by uBB Central
CVE-2026-54220

8.6HIGH

Key Information:

Vendor
CVE Published:
18 June 2026

What is CVE-2026-54220?

The uBB.threads software, developed by uBB Central, is susceptible to a Cross-Site Request Forgery (CSRF) attack due to inadequate protective measures. This vulnerability enables malicious actors to exploit an authenticated user’s session, manipulating them into performing unintended actions without their consent. While confirmed in version 7.7.5, it is advisable to assess other versions for similar vulnerabilities.

Affected Version(s)

UBB.threads 0 <= 7.7.5

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski (Securitum)
Michał Wnękowicz (Securitum)
.