vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-61511 is a critical unauthenticated remote code execution vulnerability affecting vBulletin 5.x and 6.x installations. The vulnerability exists in the vB5_Template_Runtime::runMaths() method, where an insufficiently restrictive regex filter fails to properly sanitize the pagenav[pagenumber] parameter. Attackers can bypass input validation using phpfuck-style encoding—a technique that represents PHP code using only permitted characters—to inject and execute arbitrary PHP code on the server. With a CVSS score of 9.8, this vulnerability poses an immediate threat to any organization running vulnerable vBulletin versions, as exploitation requires no authentication and can lead to complete server compromise, data theft, and lateral movement into internal networks.
While MITRE ATT&CK techniques are not formally mapped to this CVE, Casky's AI-powered analysis framework would detect the attack patterns underlying this vulnerability by identifying code injection and command execution behaviors. Practitioners using Casky would observe findings related to unsafe input handling, regex bypass techniques, and dynamic code execution (eval/assert patterns). The platform's extended reasoning capability would correlate the phpfuck encoding obfuscation tactic with CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code) to surface how attackers transform benign-appearing characters into malicious PHP payloads. Security teams would see detailed intelligence on exploitation chains, parameter manipulation patterns, and indicators of compromise that reveal when attackers attempt to exploit this template runtime flaw in their environment.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-61511. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation