LDAP Injection Vulnerability in Kanboard Project Management Software by Kanboard
CVE-2026-21880
5.3MEDIUM
What is CVE-2026-21880?
Kanboard, a project management software leveraging the Kanban methodology, is susceptible to an LDAP Injection vulnerability in versions 1.2.48 and earlier. This flaw allows user input to be directly integrated into LDAP search filters without adequate sanitization. As a consequence, attackers can exploit this vulnerability to enumerate LDAP users, potentially exposing sensitive user attributes and enabling targeted attacks on specific accounts. This issue has been addressed in version 1.2.49.
Affected Version(s)
kanboard < 1.2.49
