CVE-2026-58054: MyBB - Privilege Escalation from Limited ACP User Management to Administrator
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the basis that the permission system allows a limited administrator to grant privileges exceeding their own authorization scope, potentially constituting an insecure default configuration. Following a dispute, the MITRE TL-Root determined the behavior reflects documented and intended product design rather than a security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58054?
CVE-2026-58054 has a severity rating of high at 7.2.
How do I fix CVE-2026-58054?
To fix CVE-2026-58054, restrict the user groups a limited Admin Control Panel user can assign when creating or editing users.
What type of vulnerability is CVE-2026-58054?
CVE-2026-58054 is a privilege escalation vulnerability affecting MyBB.
Which software versions are affected by CVE-2026-58054?
CVE-2026-58054 affects MyBB version 1.8.40.
What is the primary risk associated with CVE-2026-58054?
The primary risk associated with CVE-2026-58054 is that a limited ACP user can elevate their privileges to an Administrator.