Security Flaw in MyBB Forum Software's Admin CP Recovery Codes Module
CVE-2026-45129

4.6MEDIUM

Key Information:

Vendor

Mybb

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-45129?

MyBB is an open-source forum software that is vulnerable due to insufficient validation in the Admin CP Recovery Codes module. Specifically, prior to version 1.8.40, the software allows attackers to exploit the regeneration of Two-Factor Authentication recovery codes via a specially crafted URL. This occurs because the application does not implement adequate request forgery protections on the recovery codes regeneration page accessible through GET requests, enabling same-site attackers to manipulate admin recovery codes. The vulnerability has been addressed in MyBB version 1.8.40.

Affected Version(s)

mybb < 1.8.40

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.