Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-58054: MyBB 1.8.40: Limited Admins can assign full Admin rights

CVE-2026-58054
Summary

A limited Admin can accidentally or intentionally make a user an Admin, giving them too much power. This can happen when an Admin with limited permissions is allowed to create or edit user accounts. To fix this, ensure that only full Admins can assign the Administrator usergroup.

Original title
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the Administrators group (gid 4) and its datahandl...
Original description
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the Administrators group (gid 4) and its datahandler's verify_usergroup() unconditionally returns true. An admin holding only the delegated user-management permission can assign the Administrators group to an account and escalate to the full Administrator permission set.
nvd CVSS3.1 7.2
nvd CVSS4.0 8.6
Vulnerability type
CWE-269 Improper Privilege Management
Published: 28 Jun 2026 · Updated: 22 Jul 2026 · First seen: 28 Jun 2026