PT-2026-77183 · Mybb · Mybb
CVE-2026-45734
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB versions prior to 1.8.40
Description
The built-in CAPTCHA does not consistently enforce single-use semantics, which allows remote attackers to bypass controls through challenge replay. This occurs because the
captcha::invalidate captcha() function is not called during successful validation paths in the following endpoints: 'contact.php', 'member.php?action=do resendactivation', 'member.php?action=do lostpw', 'member.php?action=do emailuser', and 'sendthread.php?action=do sendtofriend' when the MyBB Default CAPTCHA is selected via the captchaimage setting. Consequently, a valid response can be reused until the challenge expires, an incorrect response is submitted, or a non-vulnerable endpoint invalidates it.Recommendations
Update to version 1.8.40.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb