{
  "source": {
    "repository": "https://github.com/quangbahoa/vbulletin",
    "commit_sha": "6126d15ed2a4023e9efa672c387f98c3e9905d4c",
    "version": "5.1.5",
    "runtime": "Real vBulletin 5.1.5 source and original MySQL database from docker.io/cck1/vbulletin@sha256:df5a9fa87186c49101db79577a0401c07f1239bf79dd1e5d066328147f6727f8, served by Apache 2.4.25 and PHP 7.0.32 from docker.io/library/wordpress@sha256:60cbd13178ed7f629098b1b7a0104ce038d55729f89784739e1bc2eca372f64a; WordPress code was not exercised. The designated repository is vBulletin 3.8.11 and does not contain the affected path."
  },
  "finding": {
    "title": "CVE-2026-61511 vBulletin pagenav runMaths pre-authentication RCE",
    "root_cause": "Unauthenticated pagenav[pagenumber] data reaches a {vb:math} expression; runMaths retains a PHP-expressive character set and passes it to eval instead of parsing a bounded arithmetic grammar.",
    "trigger": "Credential-free POST with routestring=ajax/render/pagenav and phpfuck/XOR pagenav[pagenumber]",
    "observed_impact": "Attacker-selected operating-system command execution as the web service, proven by matching fresh response and target-local file markers."
  },
  "novelty": {
    "relationship": "duplicate",
    "advisory_status": "found",
    "public_disclosure_status": "explicit",
    "fix_reference": "vBulletin 6.2.2 and vBulletin 6.2.1/6.2.0/6.1.6 Patch Level 1",
    "compared_references": [
      "https://karmainsecurity.com/KIS-2026-13",
      "https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/",
      "https://www.cve.org/CVERecord?id=CVE-2026-61511",
      "https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6",
      "https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available",
      "https://karmainsecurity.com/pocs/CVE-2026-61511.php"
    ],
    "rationale": "The public KIS-2026-13 and SSD advisories explicitly disclose the same pagenav[pagenumber] to runMaths eval root cause, phpfuck mechanism, unauthenticated route, impact, affected range, and PoC. This runtime confirmation is therefore a duplicate of a public vulnerability, not a novel discovery or silent fix."
  },
  "evidence": {
    "positive_runs": [
      "logs/repro/durable-positive-3-proof.log",
      "logs/repro/durable-positive-3-marker.txt",
      "logs/repro/durable-positive-4-proof.log",
      "logs/repro/durable-positive-4-marker.txt"
    ],
    "negative_control": "logs/repro/durable-positive-4-baseline-response.txt"
  }
}
