PT-2026-26020 · Kanboard · Kanboard

Highfguillot

·

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-29056

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.51
Description Kanboard is project management software focused on the Kanban methodology. The user invite registration endpoint (UserInviteController::register()) accepts all POST parameters and passes them to UserModel::create() without filtering the role field. An attacker receiving an invite link can inject role=app-admin into the registration form to create an administrator account. The role parameter is vulnerable to injection.
Recommendations Versions prior to 1.2.51 should be updated to version 1.2.51 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29056
GHSA-2JVJ-Q44V-6P3X

Affected Products

Kanboard