Forum Software Vulnerability in MyBB Calendar Module
CVE-2026-45122

4.3MEDIUM

Key Information:

Vendor

Mybb

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-45122?

MyBB is a widely-used open source forum software that, in versions prior to 1.8.40, contains a vulnerability within its calendar module. This issue arises when moderation permissions are not correctly validated for the destination calendar during the event-moving process. A user with moderation rights on the source calendar can potentially move events to a target calendar where they only possess viewing privileges. This security gap is due to the absence of a proper permission check in the 'do_move' action function within calendar.php. To mitigate this vulnerability, it is essential to update to MyBB version 1.8.40 or later, which addresses this permission oversight effectively.

Affected Version(s)

mybb < 1.8.40

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.