PT-2026-26020 · Kanboard · Kanboard

Highfguillot

·

Publicado

2026-03-18

·

Atualizado

2026-03-18

·

CVE-2026-29056

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.51
Description Kanboard is project management software focused on the Kanban methodology. The user invite registration endpoint (UserInviteController::register()) accepts all POST parameters and passes them to UserModel::create() without filtering the role field. An attacker receiving an invite link can inject role=app-admin into the registration form to create an administrator account. The role parameter is vulnerable to injection.
Recommendations Versions prior to 1.2.51 should be updated to version 1.2.51 or later.

Exploit

Correção

LPE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29056
GHSA-2JVJ-Q44V-6P3X

Produtos afetados

Kanboard