Open Redirect Vulnerability in Kanboard Project Management Software
CVE-2026-21879
4.7MEDIUM
What is CVE-2026-21879?
Kanboard, a project management tool leveraging Kanban principles, is susceptible to an Open Redirect vulnerability in versions prior to 1.2.49. This flaw enables malicious entities to redirect logged-in users to harmful sites by crafting deceptive URLs, circumventing existing validation mechanisms. This exploitation can lead to various threats including phishing attempts, credential theft, and potential malware distribution. Users are strongly encouraged to upgrade to version 1.2.49 to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kanboard < 1.2.49
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
