PT-2026-77179 · Mybb · Mybb

CVE-2026-45125

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.40
Description The Email User controller fails to properly sanitize sender names, leading to mail header injection. The endpoint 'member.php?action=do emailuser' accepts the fromname parameter for guests or the stored username for authenticated users when the cansendemail group permission is active. If the mail handler is configured to the default PHP mail value, the sender name is inserted into Return-Path and Reply-To headers without sanitization, allowing the injection of arbitrary headers via CRLF (Carriage Return Line Feed) sequences. CRLF sequences are special characters used to signify the end of a line of text.
Recommendations Update to version 1.8.40.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45125
GHSA-F626-53Q9-PQM9

Affected Products

Mybb