Vulnerability in MyBB Forum Software Allows Unauthorized Changes to Admin User Views
CVE-2026-45128
3.5LOW
What is CVE-2026-45128?
MyBB forum software experienced a vulnerability in the ACP Users View Manager module that improperly validates requests. This flaw permitted same-site attackers to modify an administrator's default user view through a specially crafted URL without any request forgery protections. Specifically, changes could be made using the 'Set as Default' feature in the Admin Control Panel. The vulnerability was addressed in MyBB version 1.8.40, rectifying the request validation oversight and enhancing overall security.
Affected Version(s)
mybb < 1.8.40
