Mail Header Injection Vulnerability in MyBB Forum Software
CVE-2026-45125

5.3MEDIUM

Key Information:

Vendor

Mybb

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-45125?

MyBB, an open source forum software, was found to have a mail header injection vulnerability prior to version 1.8.40. The Email User controller inadequately sanitizes the sender names provided via the fromname HTTP parameter, which can be utilized by guests or authenticated users with email-sending permissions. This lack of sanitization can lead to the injection of arbitrary headers into the Return-Path and Reply-To fields due to CRLF sequences when the mail_handler is configured to use the default PHP mail function. This vulnerability poses a risk of exploitation if left unaddressed, but it has been rectified in version 1.8.40.

Affected Version(s)

mybb < 1.8.40

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.