PatchSiren cyber security CVE debrief
CVE-2016-9418 Mybb CVE debrief
CVE-2016-9418 is a Windows-specific information disclosure issue in MyBB and MyBB Merge System before 1.8.8. According to NVD, remote attackers could obtain sensitive information from ACP backups via a short-name related vector, with no privileges or user interaction required.
- Vendor
- Mybb
- Product
- Merge System
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-31
- Advisory updated
- 2026-05-13
Who should care
Administrators running MyBB or MyBB Merge System on Windows, especially if ACP backup files are present or reachable on hosted web servers.
Technical summary
NVD classifies the flaw as CWE-200 and assigns CVSS 3.0 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The vulnerable CPEs cover MyBB and MyBB Merge System through 1.8.7, while the issue is tied to Windows-hosted deployments of these products rather than Microsoft Windows itself.
Defensive priority
High — unauthenticated network exposure with high confidentiality impact on administrative backup data.
Recommended defensive actions
- Upgrade MyBB and MyBB Merge System to version 1.8.8 or later.
- Confirm Windows-hosted instances are not running affected versions 1.8.7 or earlier.
- Review ACP backup storage and remove any backup material that should not be web-accessible.
- Restrict access to administrative backup paths and verify they are not exposed through the web server.
- Validate the deployment after upgrade and check for any residual disclosure of sensitive backup data.
Evidence notes
The NVD record states that MyBB and MyBB Merge System before 1.8.8 on Windows may expose sensitive information from ACP backups via a short-name-related vector. It also lists CWE-200 and CVSS 3.0 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), and marks MyBB/Merge System through 1.8.7 as vulnerable CPEs. The record references the MyBB 1.8.8/merge system 1.8.8 release note and OSS-security mailing list posts from 2016-10/11 as supporting material.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9418 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9418
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9418 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9418
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/
[email protected] - Patch, Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.