Permissions Bypass in Kanboard Project Management Software
CVE-2026-25531

4.3MEDIUM

Key Information:

Vendor

Kanboard

Status
Vendor
CVE Published:
13 February 2026

What is CVE-2026-25531?

Kanboard, a project management software based on the Kanban methodology, has a vulnerability due to incomplete fixes related to user permissions. Specifically, in versions prior to 1.2.50, the TaskCreationController::duplicateProjects() endpoint fails to adequately validate whether authenticated users have permission to duplicate tasks into target projects. This flaw could allow users to access and duplicate tasks in projects they are not authorized to interact with, potentially resulting in unauthorized data exposure. The issue has been addressed in version 1.2.50, and users are encouraged to update their installations to mitigate this risk.

Affected Version(s)

kanboard < 1.2.50

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.