PT-2026-7995 · Kanboard · Kanboard

S2Ongmo

·

Published

2026-01-01

·

Updated

2026-02-13

·

CVE-2026-25531

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.50
Description Kanboard is project management software based on the Kanban method. An issue exists in the TaskCreationController::duplicateProjects() endpoint where user permissions for target projects are not validated. This allows authenticated users to duplicate tasks into projects they should not have access to.
Recommendations Update to version 1.2.50 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25531
GHSA-VRM3-3337-WHP9

Affected Products

Kanboard