PT-2026-77173 · Mybb · Mybb

CVE-2026-45119

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.40
Description The Admin CP UTF-8 Conversion module fails to validate certain requests correctly. This allows same-site attackers to alter table encoding and cause a denial of service using a specially crafted URL. Specifically, the do=all control flow in the 'admin/modules/tools/system health.php' endpoint performs ALTER TABLE operations, column rewrite phases, and fulltext index rebuilds on GET requests for the database table specified by the table parameter without proper request verification.
Recommendations Update to version 1.8.40.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45119
GHSA-P48Q-4VGF-Q7X8

Affected Products

Mybb