Security Flaw in MyBB Forum Software's Admin CP Recovery Codes Module
CVE-2026-45129
4.6MEDIUM
What is CVE-2026-45129?
MyBB is an open-source forum software that is vulnerable due to insufficient validation in the Admin CP Recovery Codes module. Specifically, prior to version 1.8.40, the software allows attackers to exploit the regeneration of Two-Factor Authentication recovery codes via a specially crafted URL. This occurs because the application does not implement adequate request forgery protections on the recovery codes regeneration page accessible through GET requests, enabling same-site attackers to manipulate admin recovery codes. The vulnerability has been addressed in MyBB version 1.8.40.
Affected Version(s)
mybb < 1.8.40
