PT-2026-7715 · Kanboard · Kanboard

Drkim-Dev

·

Publicado

2026-02-11

·

Atualizado

2026-02-14

·

CVE-2026-25924

CVSS v3.1

8.4

Alta

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.50
Description Kanboard is project management software based on the Kanban methodology. A security control bypass allows an authenticated administrator to achieve Remote Code Execution (RCE). The application does not properly verify a security setting, allowing an attacker to force the server to download and install a malicious plugin, leading to arbitrary code execution. The vulnerable endpoint bypasses the PLUGIN INSTALLER configuration when set to false.
Recommendations Update to version 1.2.50 or later.

Exploit

Correção

RCE

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25924
GHSA-GRCH-P7VF-VC4F

Produtos afetados

Kanboard