Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mybb
Mybb mybb |
|
| Vendors & Products |
Mybb
Mybb mybb |
Tue, 18 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user has only viewing permission because the do_move action in calendar.php does not check canmoderateevents for the target calendar. The uniquely identifying implementation details include calendar event move, source calendar moderation permission, and destination calendar viewing permission. This issue is fixed in version 1.8.40. | |
| Title | MyBB: Insufficient permission check for calendar event move | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T17:54:36.990Z
Reserved: 2026-05-08T20:08:17.208Z
Link: CVE-2026-45122
Updated: 2026-08-18T17:54:28.229Z
Status : Received
Published: 2026-08-18T16:17:07.243
Modified: 2026-08-18T18:17:35.967
Link: CVE-2026-45122
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:45:03Z