Forum Software Vulnerability in MyBB Calendar Module
CVE-2026-45120
5.4MEDIUM
What is CVE-2026-45120?
The MyBB forum software contains an access control vulnerability in its calendar module prior to version 1.8.40. This flaw allows users with viewing and moderation permissions to improperly access and administer private events. The module fails to consistently verify the private status of events, as evidenced by the missing checks in key functions. This oversight poses a risk of unauthorized information exposure. The issue has been addressed in version 1.8.40, which ensures proper handling of private event visibility.
Affected Version(s)
mybb < 1.8.40
