PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-9403 Mybb CVE debrief

CVE-2016-9403 affects MyBB and MyBB Merge System before 1.8.7. NVD describes a missing permission check in newreply.php that allows remote attackers to have unspecified impact. The NVD CVSS vector rates the issue as critical, with network access, no privileges, and no user interaction required.

Vendor
Mybb
Product
Merge System
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2026-05-13
Advisory published
2017-01-31
Advisory updated
2026-05-13

Who should care

Administrators and operators of MyBB forums, sites running the MyBB Merge System, and teams responsible for public-facing web applications should treat this as urgent if any instance is still on 1.8.6 or earlier.

Technical summary

NVD lists vulnerable MyBB and MyBB Merge System versions up to and including 1.8.6. The issue is described as a missing permission check in newreply.php, which can let a remote attacker trigger unspecified impact. The NVD CVSS 3.0 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a severe remotely reachable flaw.

Defensive priority

Urgent

Recommended defensive actions

  • Upgrade MyBB and MyBB Merge System to 1.8.7 or later.
  • Verify that no public or internal systems are still running version 1.8.6 or earlier.
  • Review access controls around reply and post-creation workflows, especially newreply.php.
  • Inspect forum logs for abnormal or unauthorized reply activity.
  • Use the vendor release notes and advisories referenced by NVD to confirm the fixed release path.

Evidence notes

Source material from NVD and the referenced vendor/advisory links states that MyBB and MyBB Merge System versions through 1.8.6 are vulnerable. The record was published on 2017-01-31 and references Openwall mailing list posts, a SecurityFocus entry, and MyBB 1.8.7 release notes as supporting material. The source description does not further specify the exact impact beyond 'unspecified impact.'

Sources and references

Verified primary and authoritative sources

  • CVE-2016-9403 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-9403

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-9403 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9403

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.