CVE-2026-46482: MyBB: Security Question insufficient validation

Published Aug 18, 2026
·
Updated

Impact The registration component does not validate the text-based Security Question CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details The public Registration workflow (member.php?action=doregister) accepts a hidden field questionid — expected to match the question session identifier (mybbquestionsessions.sid) — and validates the challenge answer without a fail-closed fallback for invalid identifiers. If the value is blank, forged, or expired, the request continues without a question-related error.

Patches MyBB 1.8.(...) resolves this issue with the following changes:

- Commit: https://github.com/mybb/mybb/commit/ - .patch: https://github.com/mybb/mybb/commit/.patch

References - Release Notes: https://mybb.com/versions/1.8.(...)/

For more information Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.

Contact The security team can be reached at security@mybb.com.

Affected Software

1 affected component
MyBB MyBB<1.8

Event History

Aug 18, 2026
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Sites using MyBB's public registration workflow with the text-based Security Question CAPTCHA are exposed. The affected request is member.php?action=do_register.

2

What does an attacker need to bypass the challenge?

No authentication or user interaction is required. An attacker can submit a registration request with a blank, forged, or expired question_id value so the Security Question is not rejected.

3

What is the available remediation?

Update to the release identified in the references as mybb_1840, which includes the referenced fix commit. If updating cannot happen immediately, the provided information does not identify a workaround.

4

How can I investigate whether the bypass was used?

Review registration requests for blank, forged, or expired question_id values that were accepted without a Security Question error. The data does not provide a definitive indicator of prior exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203