Project Management Software Vulnerability in Kanboard by Kanboard
CVE-2025-52576
What is CVE-2025-52576?
Kanboard, a project management tool based on the Kanban method, suffers from a significant vulnerability that allows attackers to exploit login mechanisms. Prior to version 1.2.46, the software is susceptible to username enumeration through the manipulation of trusted HTTP headers. This flaw enables attackers to identify valid usernames and, at the same time, bypass IP-based protections like Fail2Ban or CAPTCHA. Organizations running publicly accessible Kanboard instances face heightened risks as attackers can leverage this vulnerability to execute brute-force or credential stuffing attacks, increasing the potential for unauthorized access to user accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kanboard < 1.2.46
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
