CVE-2026-48780 Details
Description
Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.
A vulnerability exists in Forem, an open-source community-building platform, allowing attackers to bypass domain allowlist or denylist restrictions by using a maliciously crafted email address. This could grant access to invite-only Forem deployments. The vulnerability affects all versions prior to commit a2ab6d4.
Users can update to Forem version a2ab6d4 or later to address this vulnerability. Some SMTP servers and email delivery providers may also drop or refuse to send maliciously crafted email addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 16, 2026CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/forem/forem/commit/a2ab6d409d2676eb0711ecbd737192043125b437 | [email protected] | Source CodeVendor |
| https://github.com/forem/forem/security/advisories/GHSA-3g4h-9h37-mpx6 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Forem | < a2ab6d4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | New CVE Received | [email protected] |
Volerion