PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45120 mybb CVE debrief

CVE-2026-45120 MyBB Calendar Module Private Event Access. The MyBB calendar module prior to version 1.8.40 does not consistently verify private event status, allowing users with viewing and moderation permissions to access and moderate private events. This issue affects MyBB users and administrators who need to assess exposure and apply updates to prevent unauthorized access to private events. The vulnerability is fixed in version 1.8.40, and users should verify their current version and apply updates if necessary.

Vendor
mybb
Product
Unknown
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-08
Advisory published
2026-08-18
Advisory updated
2026-09-08

Who should care

MyBB users and administrators should assess exposure and apply updates to prevent unauthorized access to private events. This includes reviewing user permissions and access controls, verifying private event access controls, and applying updates to prevent unauthorized access. Security teams and platform administrators should prioritize this vulnerability and take action to protect against potential exploitation.

Why it matters

CVE-2026-45120 allows users with viewing and moderation permissions to access and moderate private events in MyBB prior to version 1.8.40. MyBB users and administrators should assess exposure and apply updates to prevent unauthorized access to private events.

  • Verify private event access controls
  • Assess user permission configurations
  • Apply updates to prevent unauthorized access

Technical summary

The MyBB calendar module prior to version 1.8.40 does not consistently verify private event status, allowing users with viewing and moderation permissions to access and moderate private events. This vulnerability affects MyBB deployments where users have viewing and moderation permissions, and administrators should assess exposure and apply updates to prevent unauthorized access to private events. The issue is fixed in version 1.8.40, and technical details are limited to CVE and NVD records describing the vulnerability.

Defensive priority

Assess exposure and apply updates

Recommended defensive actions

  • Assess exposure to the MyBB calendar module
  • Verify current version and apply updates if necessary
  • Review user permissions and access controls
  • Verify private event access controls
  • Assess user permission configurations
  • Apply updates to prevent unauthorized access
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and NVD entry provide details on the MyBB calendar module vulnerability. The issue allows users with viewing and moderation permissions to access and moderate private events prior to version 1.8.40. Evidence is limited to public CVE and NVD records, which describe the vulnerability and its fix. Defenders should verify private event access controls, assess user permission configurations, and apply updates to prevent unauthorized access.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45120 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45120

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45120 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45120

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.