PatchSiren cyber security CVE debrief
CVE-2026-45122 mybb CVE debrief
CVE-2026-45122 is a vulnerability in MyBB forum software prior to version 1.8.40, where the calendar module fails to validate moderation permissions when moving events between calendars. A user with moderation permission for the source calendar can move an event to a calendar where they only have viewing permission. This issue is fixed in version 1.8.40.
- Vendor
- mybb
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
MyBB administrators, security teams, and users with moderation permissions should assess exposure and apply patches to prevent potential unauthorized calendar actions. Security teams should verify user permissions, monitor for suspicious event moves, and review incident response plans. Affected operators and platforms should prioritize patching and review compensating controls for exposed systems.
Why it matters
CVE-2026-45122 is a medium-severity vulnerability in MyBB forum software that allows users with moderation permission to move events to calendars where they only have viewing permission. This could lead to unauthorized actions if exploited. MyBB administrators and security teams should assess exposure, verify user permissions, and apply patches to prevent potential abuse.
- Verify user permissions to prevent unauthorized event moves
- Monitor for suspicious event moves to detect potential abuse
- Apply patches to prevent exploitation of this vulnerability
Technical summary
The calendar module in MyBB prior to 1.8.40 does not validate moderation permissions when moving events between calendars. A user with moderation permission for the source calendar can move an event to a calendar where they only have viewing permission, potentially allowing unauthorized actions. This issue is fixed in version 1.8.40, which includes the necessary permission checks to prevent such moves. MyBB administrators should assess exposure and apply patches to prevent potential unauthorized calendar actions. The vulnerability has a medium severity score of 4.3 and is fixed in version 1.8.40.
Defensive priority
Assess exposure and apply patches for MyBB installations, verify user permissions and monitor for suspicious event moves
Recommended defensive actions
- Assess MyBB installation exposure and apply patches
- Verify user permissions and monitor for suspicious event moves
- Review and update incident response plans for potential calendar abuse
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 1.8.40. However, additional information on exploitation or affected deployments is limited. Defenders should verify MyBB installations, user permissions, and monitor for suspicious event moves. Limited source detail suggests cautious verification of affected scope and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45122 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45122
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45122 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45122
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/mybb/mybb/commit/86ed2058e7f9a2c14828e731f684e997f9bb220c
-
Source reference
Unverified legacy reference
URL: https://github.com/mybb/mybb/releases/tag/mybb_1840
-
Source reference
Unverified legacy reference
URL: https://github.com/mybb/mybb/security/advisories/GHSA-839m-gpw8-59j4
-
Source reference
Unverified legacy reference
URL: https://mybb.com/versions/1.8.40
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.