Permissions Bypass in Kanboard Project Management Software
CVE-2026-25531
4.3MEDIUM
What is CVE-2026-25531?
Kanboard, a project management software based on the Kanban methodology, has a vulnerability due to incomplete fixes related to user permissions. Specifically, in versions prior to 1.2.50, the TaskCreationController::duplicateProjects() endpoint fails to adequately validate whether authenticated users have permission to duplicate tasks into target projects. This flaw could allow users to access and duplicate tasks in projects they are not authorized to interact with, potentially resulting in unauthorized data exposure. The issue has been addressed in version 1.2.50, and users are encouraged to update their installations to mitigate this risk.
Affected Version(s)
kanboard < 1.2.50
