PT-2026-77184 · Mybb · Mybb

CVE-2026-46482

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.(...)
Description The registration component fails to correctly validate the text-based Security Question CAPTCHA, which allows attackers to bypass the challenge using a specially crafted value. In the public registration workflow at the endpoint 'member.php?action=do register', the system accepts a hidden field question id that should match the question session identifier mybb questionsessions.sid. The validation process lacks a fail-closed fallback for invalid identifiers; consequently, if the question id is blank, forged, or expired, the request proceeds without triggering a question-related error.
Recommendations Update MyBB to version 1.8.(...) or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46482
GHSA-V2H7-4JP7-J6HH

Affected Products

Mybb