{"apiVersion":"1.0","identifier":"CVE-2026-47245","description":"MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate reciprocal buddy-list updates correctly. The usercp.php?action=do_editlists delete handler removes the selected entry from the acting user-s list and then updates mybb_users.buddylist for the target account. The reciprocal update searches for the deleted target UID instead of the acting user-s UID and uses the unchecked array_search() return value as an array key. A false result can be converted to index 0, removing the target account-s first stored buddy while leaving the actual reciprocal entry unchanged. The uniquely identifying implementation details include false converted to index 0. This issue is fixed in version 1.8.40.","publishedAt":"2026-08-18T16:17:09","lastModifiedAt":"2026-08-18T18:17:38","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47245","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","epssProbability":0.00269,"riskScore":0.44,"affectedProduct":"MyBB","affectedVersions":"<1.8.40","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-47245","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-47245","en":"https://www.redsauce.net/en/cves/CVE-2026-47245","fr":"https://www.redsauce.net/fr/cves/CVE-2026-47245","pt":"https://www.redsauce.net/pt/cves/CVE-2026-47245","de":"https://www.redsauce.net/de/cves/CVE-2026-47245","sk":"https://www.redsauce.net/sk/cves/CVE-2026-47245","el":"https://www.redsauce.net/el/cves/CVE-2026-47245"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-47245"}}