A privilege-boundary flaw in MyBB 1.8.40 allows an Admin Control Panel account with only limited user-management rights to create a new user in the full Administrator group and escalate to unrestricted administrative access. The issue affects the Admin CP add-user workflow, where administrator-capable groups are exposed to lower-privileged admins and submitted group values are accepted without an effective authorization check, enabling creation of an account with gid=4 and access to modules that were previously denied.
A public proof of concept published on GitHub said the behavior was verified on a fresh MyBB 1.8.40 installation, showing that a non-super admin could promote a newly created account into the top administrator role. The reported impact includes full MyBB application administration, such as changing configuration, modifying permissions, managing users, and altering themes, templates, and other persistence-relevant settings. The researcher recommended blocking limited ACP users from assigning ACP-capable groups in add-user, edit-user, and bulk-update flows, and enforcing group-grant restrictions inside UserDataHandler::verify_usergroup().

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On a fresh MyBB 1.8.40 installation, a researcher verified that a non-super Admin CP account with only user-management permissions could create a new account in the Administrator group and gain full administrator capabilities. The test on 18 June 2026 confirmed the source account was denied access to config-settings before exploitation, while the newly created gid=4 account could access previously denied modules afterward.
MyBB version 1.8.40 was released. Later reporting states this version contained the limited-ACP-to-admin privilege-escalation issue and also patched an older stored XSS issue tracked as CVE-2026-45115.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.