PT-2026-77178 · Mybb · Mybb

CVE-2026-45124

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.40
Description The Mod CP Report Center fails to consistently verify permissions, enabling moderators who lack report-management privileges to mark reports as resolved. The handler for the endpoint 'modcp.php?action=do reports' (Mark Selected as Read) is accessible to users with canmodcp permissions, even if they lack canmanagereportedcontent or canmanagereportedposts. When no forums are in scope, the variable $flist reports remains empty, causing the UPDATE mybb reportedcontent query to execute without the required permission-based restrictions.
Recommendations Update to version 1.8.40.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45124
GHSA-GFXJ-G7W6-6W4V

Affected Products

Mybb