PT-2026-53086 · Mybb · Mybb
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyBB version 1.8.40
Description
An issue exists where users with limited Admin Control Panel (ACP) access can assign any usergroup to an account during creation or editing. This occurs because the
verify usergroup() function in the user module datahandler unconditionally returns true for the Administrators group (gid 4). Consequently, an administrator with only delegated user-management permissions can assign the Administrators group to an account, leading to a privilege escalation to the full Administrator permission set.Recommendations
Update MyBB to a version newer than 1.8.40.
Review and restrict user permissions within the Admin Control Panel to minimize the risk of unauthorized group assignment.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb