Forum Software Vulnerability in MyBB Calendar Module
CVE-2026-45122
4.3MEDIUM
What is CVE-2026-45122?
MyBB is a widely-used open source forum software that, in versions prior to 1.8.40, contains a vulnerability within its calendar module. This issue arises when moderation permissions are not correctly validated for the destination calendar during the event-moving process. A user with moderation rights on the source calendar can potentially move events to a target calendar where they only possess viewing privileges. This security gap is due to the absence of a proper permission check in the 'do_move' action function within calendar.php. To mitigate this vulnerability, it is essential to update to MyBB version 1.8.40 or later, which addresses this permission oversight effectively.
Affected Version(s)
mybb < 1.8.40
