Vulnerability in MyBB Forum Software Allows Unauthorized Changes to Admin User Views
CVE-2026-45128

3.5LOW

Key Information:

Vendor

Mybb

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-45128?

MyBB forum software experienced a vulnerability in the ACP Users View Manager module that improperly validates requests. This flaw permitted same-site attackers to modify an administrator's default user view through a specially crafted URL without any request forgery protections. Specifically, changes could be made using the 'Set as Default' feature in the Admin Control Panel. The vulnerability was addressed in MyBB version 1.8.40, rectifying the request validation oversight and enhancing overall security.

Affected Version(s)

mybb < 1.8.40

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.