PT-2026-77178 · Mybb · Mybb
CVE-2026-45124
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB versions prior to 1.8.40
Description
The Mod CP Report Center fails to consistently verify permissions, enabling moderators who lack report-management privileges to mark reports as resolved. The handler for the endpoint 'modcp.php?action=do reports' (Mark Selected as Read) is accessible to users with
canmodcp permissions, even if they lack canmanagereportedcontent or canmanagereportedposts. When no forums are in scope, the variable $flist reports remains empty, causing the UPDATE mybb reportedcontent query to execute without the required permission-based restrictions.Recommendations
Update to version 1.8.40.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb