CVE-2026-45734 | MyBB up to 1.8.39 Captcha contact.php invalidate_captcha captchaimage authentication replay
A vulnerability was found in MyBB up to 1.8.39. It has been declared as critical. Affected by this issue is the function captcha::invalidate_captcha of the file contact.php of the component Captcha. Executing a manipulation of the argument captchaimage can lead to authentication bypass by capture-replay.
This vulnerability is registered as CVE-2026-45734. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More