Medium severity4.3NVD Advisory· Published Aug 18, 2026
CVE-2026-45124
CVE-2026-45124
Description
MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is reachable with canmodcp even without canmanagereportedcontent or canmanagereportedposts. When no forums are in scope, $flist_reports is empty and the UPDATE mybb_reportedcontent query executes without the expected permission-based limitation. This issue is fixed in version 1.8.40.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.