PatchSiren cyber security CVE debrief
CVE-2016-9411 Mybb CVE debrief
CVE-2016-9411 is an information-disclosure issue in MyBB and MyBB Merge System before 1.8.7. According to the NVD record, a remote attacker could learn the installation path through mail-related vectors in the Admin control panel. The issue is rated medium severity (CVSS 5.3) and maps to CWE-200. The practical fix is to move affected deployments to 1.8.7 or later and confirm that older releases are no longer exposed.
- Vendor
- Mybb
- Product
- Merge System
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-31
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators running MyBB or MyBB Merge System versions 1.8.6 and earlier, especially any instance that exposes the Admin control panel or mail-sending functionality to untrusted users or the internet.
Technical summary
NVD classifies the flaw as a network-reachable, low-complexity issue with no privileges or user interaction required and limited confidentiality impact. The vulnerable products are MyBB and MyBB Merge System through 1.8.6. The published description says remote attackers can obtain the installation path via mail-related vectors in the Admin control panel. This is an information disclosure weakness rather than a code execution or denial-of-service issue.
Defensive priority
Medium priority. The vulnerability exposes internal path information and affects older supported and unsupported versions, but the published impact is limited to confidentiality.
Recommended defensive actions
- Upgrade MyBB and MyBB Merge System to version 1.8.7 or later.
- Inventory all deployments and verify that no 1.8.6-or-earlier instances remain in production, staging, or backups exposed to users.
- Review admin panel access controls and reduce exposure of mail-related administrative features to only trusted administrators.
- Check for any configuration, logging, or error-handling settings that could further reveal filesystem paths.
- Use the vendor advisory and NVD record to validate that the installed version is outside the affected range.
Evidence notes
This debrief is based on the supplied NVD record and official references only. The record lists affected CPEs for mybb:mybb and mybb:merge_system through 1.8.6, CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, and CWE-200 as the primary weakness. Supporting references include OSS-security mailing list posts, a SecurityFocus entry, and the MyBB release note/advisory link.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9411 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9411
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9411 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9411
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blog.mybb.com/2016/03/11/mybb-1-8-7-merge-system-1-8-7-release/
[email protected] - Patch, Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.