CVE-2026-45129

medium

Description

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Admin CP Home, Preferences, Recovery Codes action=recovery_codes page regenerates Two-Factor Authentication recovery codes in mybb_adminoptions.recovery_codes on GET requests without request forgery protection. The uniquely identifying implementation details include admin/modules/home/preferences.php. This issue is fixed in version 1.8.40.

References

https://mybb.com/versions/1.8.40

https://github.com/mybb/mybb/security/advisories/GHSA-75vg-6wgp-mcc9

https://github.com/mybb/mybb/releases/tag/mybb_1840

https://github.com/mybb/mybb/commit/d2d9e47b53d85101cf25cb47e882bc7ba76355a4

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-61019

Details

Source: Mitre, NVD

Published: 2026-08-18

Updated: 2026-09-08

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 4.6

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00182