Authenticated SQL Injection Vulnerability in Kanboard Project Management Software
CVE-2026-33058
8.4HIGH
What is CVE-2026-33058?
Kanboard is a project management tool that implements the Kanban methodology. It has been discovered that versions prior to 1.2.51 contain an authenticated SQL injection vulnerability. This issue allows attackers with permissions to add users to a project to exploit the vulnerability, enabling them to extract sensitive information from the entire Kanboard database. Upgrading to version 1.2.51 or later resolves this security flaw.
Affected Version(s)
kanboard < 1.2.51
