MEDIUM
MyBB: Mod CP report resolution missing authorization
Published Aug 18, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.34%
Description
MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is reachable with canmodcp even without canmanagereportedcontent or canmanagereportedposts. When no forums are in scope, $flist_reports is empty and the UPDATE mybb_reportedcontent query executes without the expected permission-based limitation. This issue is fixed in version 1.8.40.
Affected products
-
- Version < 1.8.40StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-61018 Advisory
- https://github.com/mybb/mybb/commit/5cda5f6d183bc2cac24f0533e8d3060a9a46cc42 x_refsource_MISC
- https://github.com/mybb/mybb/releases/tag/mybb_1840 x_refsource_MISC
- https://github.com/mybb/mybb/security/advisories/GHSA-gfxj-g7w6-6w4v x_refsource_CONFIRM
- https://mybb.com/versions/1.8.40 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-61018 | Advisory | |
| https://github.com/mybb/mybb/commit/5cda5f6d183bc2cac24f0533e8d3060a9a46cc42 | x_refsource_MISC | |
| https://github.com/mybb/mybb/releases/tag/mybb_1840 | x_refsource_MISC | |
| https://github.com/mybb/mybb/security/advisories/GHSA-gfxj-g7w6-6w4v | x_refsource_CONFIRM | |
| https://mybb.com/versions/1.8.40 | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 18, 2026
Updated Aug 19, 2026
Reserved May 8, 2026
Link CVE-2026-45124
CISA Vulnrichment
Updated Aug 19, 2026
ENISA EUVD
EUVD-2026-61018 Assigner GitHub_M
Published Aug 18, 2026
Updated Aug 19, 2026
Exploited since n/a
Link EUVD-2026-61018