Forum Software Vulnerability in MyBB Calendar Module
CVE-2026-45120

5.4MEDIUM

Key Information:

Vendor

Mybb

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-45120?

The MyBB forum software contains an access control vulnerability in its calendar module prior to version 1.8.40. This flaw allows users with viewing and moderation permissions to improperly access and administer private events. The module fails to consistently verify the private status of events, as evidenced by the missing checks in key functions. This oversight poses a risk of unauthorized information exposure. The issue has been addressed in version 1.8.40, which ensures proper handling of private event visibility.

Affected Version(s)

mybb < 1.8.40

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.