CVE-2026-58054: exploitation status and patch state

CVE-2026-58054 · CVSS 7.2 HIGH · EPSS <1%

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the Administrators group (gid 4) and its datahandler's verify_usergroup() unconditionally returns true. An admin holding only the delegated user-management permission can assign the Administrators group to an account and escalate to the full Administrator permission set.

Is CVE-2026-58054 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-58054

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-12.