Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
A public exploit has been released for a patched vBulletin pre-auth code execution flaw. The exploit requires no account, administrative access, or interaction from another user and can execute code on an unpatched forum server.
Intelligence analysis by Llama

A public exploit has been released for a patched vBulletin pre-auth code execution flaw. The exploit requires no account, administrative access, or interaction from another user and can execute code on an unpatched forum server. Administrators running self-hosted installations should apply the patch for their branch or upgrade to 6.2.2.
Imagine you have a website where people can talk to each other. But instead of using a special button to post a message, someone can just type in a special code that makes the website do something bad. This is what happened with the vBulletin website. Someone found a way to make the website do something bad without needing a special button or permission. This is a big problem because it means that people who run websites like vBulletin need to make sure they are keeping their software up to date so that they can fix any problems like this.
Analysis
A $60B Vote of Confidence
The recent public exploit released for the patched vBulletin pre-auth code execution flaw has raised concerns about the security of internet-facing forums. The exploit, which requires no account, administrative access, or interaction from another user, can execute code on an unpatched forum server. This highlights the importance of keeping software up to date, especially when it comes to security patches.
The exploit targets a vulnerability in the vBulletin template engine, which was patched in June 2026. However, the patch was not widely applied, and many internet-facing forums are still running the vulnerable builds. This has led to a situation where a quiet fix goes out first, a working exploit surfaces weeks later, and by then many internet-facing forums are still running the vulnerable builds.
The exploit's own banner calls the issue a zero-day, but the vendor's patches and the 6.2.2 release preceded public disclosure by nearly four weeks. The exploit code is new; the flaw it targets was already fixed. With Cloud reportedly patched and the self-hosted fixes nearly a month old, the live risk is concentrated in self-hosted, internet-facing forums that have not updated, a more specific population than a bare 'vBulletin RCE' implies.
Defenders can review POST requests carrying routestring=ajax/render/pagenav with unusually long or operator-heavy pagenav[pagenumber] values, a pattern derived from the public PoC rather than vendor detection guidance. This is the same corner of vBulletin that has produced pre-authentication code execution before. The May 2025 chain, CVE-2025-48827 and CVE-2025-48828, abused the template engine through a different path and drew exploitation attempts within days of disclosure, after the vendor had quietly patched it months earlier and many forums never applied the fix.
Each round has run the same way. A quiet fix goes out first, a working exploit surfaces weeks later, and by then many internet-facing forums are still running the vulnerable builds. This highlights the importance of keeping software up to date, especially when it comes to security patches.
Why Cursor?
The exploit's own banner calls the issue a zero-day, but the vendor's patches and the 6.2.2 release preceded public disclosure by nearly four weeks. The exploit code is new; the flaw it targets was already fixed. With Cloud reportedly patched and the self-hosted fixes nearly a month old, the live risk is concentrated in self-hosted, internet-facing forums that have not updated, a more specific population than a bare 'vBulletin RCE' implies.
The Road Ahead
The recent public exploit released for the patched vBulletin pre-auth code execution flaw has raised concerns about the security of internet-facing forums. The exploit, which requires no account, administrative access, or interaction from another user, can execute code on an unpatched forum server. This highlights the importance of keeping software up to date, especially when it comes to security patches.
The exploit targets a vulnerability in the vBulletin template engine, which was patched in June 2026. However, the patch was not widely applied, and many internet-facing forums are still running the vulnerable builds. This has led to a situation where a quiet fix goes out first, a working exploit surfaces weeks later, and by then many internet-facing forums are still running the vulnerable builds.
Key points
- A public exploit has been released for a patched vBulletin pre-auth code execution flaw.
- The exploit requires no account, administrative access, or interaction from another user and can execute code on an unpatched forum server.
- Administrators running self-hosted installations should apply the patch for their branch or upgrade to 6.2.2.
- The exploit targets a vulnerability in the vBulletin template engine, which was patched in June 2026.
- However, the patch was not widely applied, and many internet-facing forums are still running the vulnerable builds.
The fact that the exploit was released after the vendor had patched the vulnerability suggests that the risk is now concentrated in self-hosted, internet-facing forums that have not updated. This means that defenders can review POST requests carrying routestring=ajax/render/pagenav with unusually long or operator-heavy pagenav[pagenumber] values, a pattern derived from the public PoC rather than vendor detection guidance. This is a more specific population than a bare 'vBulletin RCE' implies.
The recent public exploit released for the patched vBulletin pre-auth code execution flaw has raised concerns about the security of internet-facing forums. The exploit, which requires no account, administrative access, or interaction from another user, can execute code on an unpatched forum server. This highlights the importance of keeping software up to date, especially when it comes to security patches.



