PT-2026-77183 · Mybb · Mybb

CVE-2026-45734

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.40
Description The built-in CAPTCHA does not consistently enforce single-use semantics, which allows remote attackers to bypass controls through challenge replay. This occurs because the captcha::invalidate captcha() function is not called during successful validation paths in the following endpoints: 'contact.php', 'member.php?action=do resendactivation', 'member.php?action=do lostpw', 'member.php?action=do emailuser', and 'sendthread.php?action=do sendtofriend' when the MyBB Default CAPTCHA is selected via the captchaimage setting. Consequently, a valid response can be reused until the challenge expires, an incorrect response is submitted, or a non-vulnerable endpoint invalidates it.
Recommendations Update to version 1.8.40.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45734
GHSA-JRRR-F3JW-MJMC

Affected Products

Mybb