CVE-2026-45734: MyBB: Default CAPTCHA missing invalidation

Published Aug 18, 2026
·
Updated

MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass CAPTCHA controls through challenge replay. The successful validation paths in contact.php, member.php?action=doresendactivation, member.php?action=dolostpw, member.php?action=doemailuser, and sendthread.php?action=dosendtofriend do not call captcha::invalidatecaptcha() for the MyBB Default CAPTCHA selected by the captchaimage setting. A valid response can therefore be reused until a non-vulnerable endpoint invalidates it, an incorrect response is submitted, or the challenge expires. This issue is fixed in version 1.8.40.

Affected Software

1 affected component
MyBB MyBB<1.8.40

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MyBB (built-in CAPTCHA) to a version that resolves this vulnerability.

    Fixed in 1.8.40

Event History

Aug 18, 2026
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments and features are affected?

Forums running MyBB versions earlier than 1.8.40 are affected when the built-in MyBB Default CAPTCHA is selected through the captchaimage setting. The affected validation paths are the contact form, activation resend, password recovery, email-user, and send-to-friend functions.

2

What does an attacker need to exploit the issue?

An attacker needs one valid answer for a CAPTCHA challenge and can replay it against the affected successful-validation paths. The challenge remains reusable until it expires, an incorrect response is submitted, or a non-vulnerable endpoint invalidates it.

3

What is the remediation?

Upgrade MyBB to version 1.8.40, which fixes the missing CAPTCHA invalidation. Until then, avoid relying on the built-in Default CAPTCHA as a single-use control for the affected workflows.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203