PatchSiren cyber security CVE debrief
CVE-2026-45120 mybb CVE debrief
CVE-2026-45120 MyBB Calendar Module Private Event Access. The MyBB calendar module prior to version 1.8.40 does not consistently verify private event status, allowing users with viewing and moderation permissions to access and moderate private events. This issue affects MyBB users and administrators who need to assess exposure and apply updates to prevent unauthorized access to private events. The vulnerability is fixed in version 1.8.40, and users should verify their current version and apply updates if necessary.
- Vendor
- mybb
- Product
- Unknown
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
MyBB users and administrators should assess exposure and apply updates to prevent unauthorized access to private events. This includes reviewing user permissions and access controls, verifying private event access controls, and applying updates to prevent unauthorized access. Security teams and platform administrators should prioritize this vulnerability and take action to protect against potential exploitation.
Why it matters
CVE-2026-45120 allows users with viewing and moderation permissions to access and moderate private events in MyBB prior to version 1.8.40. MyBB users and administrators should assess exposure and apply updates to prevent unauthorized access to private events.
- Verify private event access controls
- Assess user permission configurations
- Apply updates to prevent unauthorized access
Technical summary
The MyBB calendar module prior to version 1.8.40 does not consistently verify private event status, allowing users with viewing and moderation permissions to access and moderate private events. This vulnerability affects MyBB deployments where users have viewing and moderation permissions, and administrators should assess exposure and apply updates to prevent unauthorized access to private events. The issue is fixed in version 1.8.40, and technical details are limited to CVE and NVD records describing the vulnerability.
Defensive priority
Assess exposure and apply updates
Recommended defensive actions
- Assess exposure to the MyBB calendar module
- Verify current version and apply updates if necessary
- Review user permissions and access controls
- Verify private event access controls
- Assess user permission configurations
- Apply updates to prevent unauthorized access
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide details on the MyBB calendar module vulnerability. The issue allows users with viewing and moderation permissions to access and moderate private events prior to version 1.8.40. Evidence is limited to public CVE and NVD records, which describe the vulnerability and its fix. Defenders should verify private event access controls, assess user permission configurations, and apply updates to prevent unauthorized access.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45120 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45120
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45120 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45120
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/mybb/mybb/commit/c077e6c29755187c4df78a1e674dd61bc55701b3
-
Source reference
Unverified legacy reference
URL: https://github.com/mybb/mybb/releases/tag/mybb_1840
-
Source reference
Unverified legacy reference
URL: https://github.com/mybb/mybb/security/advisories/GHSA-c2hm-g9w6-pv6x
-
Source reference
Unverified legacy reference
URL: https://mybb.com/versions/1.8.40
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.